CVE Explorer
CVE-2026-23522
LobeChat is an open source chat application platform. Prior to version 2.0.0-next.193, `knowledgeBase.removeFilesFromKnowledgeBase` tRPC ep allows authenticated users to delete files from any knowledge base without verifying ownership. `userId` filter in the database query is commented out, so it's enabling attackers to delete other users' KB files if they know the knowledge base ID and file ID. While the vulnerability is confirmed, practical exploitation requires knowing target's KB ID and targ
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 4 assertions
{"cweId":"CWE-639","description":"CWE-639: Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:0f69224ca14bcf0c6710d1ed914eaf2e4f6133e22a27be7419ae10a03e52f64b · sha256:da5ea504a4d73b11… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-862","description":"CWE-862: Missing Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:0f69224ca14bcf0c6710d1ed914eaf2e4f6133e22a27be7419ae10a03e52f64b · sha256:da5ea504a4d73b11… · /containers/cna/problemTypes/2/descriptions/0
{"cweId":"CWE-284","description":"CWE-284: Improper Access Control","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:0f69224ca14bcf0c6710d1ed914eaf2e4f6133e22a27be7419ae10a03e52f64b · sha256:da5ea504a4d73b11… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-915","description":"CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:0f69224ca14bcf0c6710d1ed914eaf2e4f6133e22a27be7419ae10a03e52f64b · sha256:da5ea504a4d73b11… · /containers/cna/problemTypes/3/descriptions/0
Affected products and versions
1 source assertion{"product":"lobe-chat","vendor":"lobehub","versions":[{"status":"affected","version":"< 2.0.0-next.193"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:0f69224ca14bcf0c6710d1ed914eaf2e4f6133e22a27be7419ae10a03e52f64b · sha256:da5ea504a4d73b11… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":3.7,"baseSeverity":"LOW","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:0f69224ca14bcf0c6710d1ed914eaf2e4f6133e22a27be7419ae10a03e52f64b · sha256:da5ea504a4d73b11… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
4 source assertions{"cweId":"CWE-639","description":"CWE-639: Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:0f69224ca14bcf0c6710d1ed914eaf2e4f6133e22a27be7419ae10a03e52f64b · sha256:da5ea504a4d73b11… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-862","description":"CWE-862: Missing Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:0f69224ca14bcf0c6710d1ed914eaf2e4f6133e22a27be7419ae10a03e52f64b · sha256:da5ea504a4d73b11… · /containers/cna/problemTypes/2/descriptions/0
{"cweId":"CWE-284","description":"CWE-284: Improper Access Control","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:0f69224ca14bcf0c6710d1ed914eaf2e4f6133e22a27be7419ae10a03e52f64b · sha256:da5ea504a4d73b11… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-915","description":"CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:0f69224ca14bcf0c6710d1ed914eaf2e4f6133e22a27be7419ae10a03e52f64b · sha256:da5ea504a4d73b11… · /containers/cna/problemTypes/3/descriptions/0
Source references
2 source assertions{"name":"https://github.com/lobehub/lobe-chat/commit/2c1762b85acb84467ed5e799afe1499cd2f912e6","tags":["x_refsource_MISC"],"url":"https://github.com/lobehub/lobe-chat/commit/2c1762b85acb84467ed5e799afe1499cd2f912e6"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:0f69224ca14bcf0c6710d1ed914eaf2e4f6133e22a27be7419ae10a03e52f64b · sha256:da5ea504a4d73b11… · /containers/cna/references/1
{"name":"https://github.com/lobehub/lobe-chat/security/advisories/GHSA-j7xp-4mg9-x28r","tags":["x_refsource_CONFIRM"],"url":"https://github.com/lobehub/lobe-chat/security/advisories/GHSA-j7xp-4mg9-x28r"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:0f69224ca14bcf0c6710d1ed914eaf2e4f6133e22a27be7419ae10a03e52f64b · sha256:da5ea504a4d73b11… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.