Unauthorized File Deletion in LobeChat by LobeHub
CVE-2026-23522

3.7LOW

Key Information:

Vendor

Lobehub

Status
Vendor
CVE Published:
19 January 2026

What is CVE-2026-23522?

LobeChat, an open-source chat application developed by LobeHub, contains a security flaw in its knowledgeBase.removeFilesFromKnowledgeBase tRPC endpoint. This allows authenticated users to delete files from other users' knowledge bases without proper authorization checks. The vulnerability arises because the userId filter in the database query is commented out, which means that any authenticated user can potentially delete files if they possess knowledge of the target knowledge base ID and the file ID. Although the IDs are randomly generated and not easily guessable, they may be exposed through shared links or logs. Users must upgrade to version 2.0.0-next.193 to prevent unauthorized file deletions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

lobe-chat < 2.0.0-next.193

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.