Executive brief
Open WebUI is an interface for interacting with large language models. A security flaw allows any logged-in user to permanently delete, read, or modify files belonging to other users if those files have been shared in a chat. This could lead to the loss of important documents, unauthorized access to private data, and the corruption of shared knowledge bases used by the organization.
Technical details
An authorization bypass exists in the `has_access_to_file()` function within `backend/open_webui/routers/files.py`. The function contains a logic branch that grants access if a file is associated with any shared chat, but it fails to verify the identity of the requesting user or the type of operation (e.g., 'read' vs 'write') being performed. An authenticated attacker can obtain file UUIDs via the knowledge base API and then use the `DELETE /api/v1/files/{id}` endpoint to permanently remove files from the database and disk. The vulnerability also affects GET and POST endpoints for file content. The issue was resolved in version 0.9.0 by refactoring the shared-chat logic to use a permission-aware access control system.
Affected products
- Open WebUI Open WebUI <= 0.8.12
Timeline
- 2026-04: patched: First released in v0.9.0
- 2026-05-11: disclosed
- 2026-05-14: advisory