Description
knowledgeBase.removeFilesFromKnowledgeBase tRPC ep allows authenticated users to delete files from any knowledge base without verifying ownership.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.143.2
References
Could your website be exposed too?
SmartScanner can check your website for Lobe Chat has IDOR in Knowledge Base File Removal that Allows Cross User File Deletion and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Lobe Chat affected by Cross-Site Scripting(XSS) that can escalate to Remote Code Execution(RCE) - CVE-2026-23733
- SillyTavern has a path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directory - CVE-2026-34522
- CryptPad has a Sanitizer Bypass in Diffmarked.js that Allows Arbitrary HTML Injection and Potential XSS - CVE-2026-26028
- lobe-chat has an Open Redirect - CVE-2025-59426
You might also like:
See something that needs correcting? Let us knowUpdated January 20, 2026


