HIGH 8.1 GitHub
CVE-2026-70494
Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder
## Summary
A user granted write access to a shared chat folder could permanently delete chats and messages belonging to the folder's owner. Deleting a folder cascades into the owner's chats and the entire subfolder subtree, and the deletion handler required only write access on subfolders instead of ownership. Root folders were restricted to the owner or an admin, subfolders were not.
## Preconditions
The Folders Sharing permission (`user.permissions.sharing.folders`) must be enabled; it is off
Affected Products
- pip/open-webui >= 0.10.0, < 0.11.0
References
- https://github.com/advisories/GHSA-3cg5-48j3-v4gv
- https://github.com/open-webui/open-webui/security/advisories/GHSA-3cg5-48j3-v4gv
- https://github.com/open-webui/open-webui/pull/27003
- https://github.com/open-webui/open-webui/commit/915ef7d0798d3175819cedbb2f62d7bf0db78c98
This high severity vulnerability with a CVSS score of 8.1 was published on 2026-08-04 via GitHub. Affected: pip/open-webui >= 0.10.0, < 0.11.0.
vulnfeed aggregates 9214 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.