How to use this reference
Editorial review principle: enforce ownership at the mutation, including every relationship being removed. Random identifiers reduce accidental discovery but do not prove permission. Review negative cross-owner cases and verify which underlying objects a removal actually changes.
Before reading
- Object ownership and relationship-level authorization
- Retrieval-augmented generation knowledge-base lifecycle
Context and limits
- The advisory credits DenizParlak as Reporter but does not display an explicit author byline. Reporter credit alone does not establish advisory authorship, so named authors remain unestablished.
- CVE-2026-23522 requires authentication and knowledge of both relevant identifiers according to the narrative; its displayed severity vector instead says no privileges. Preserve that discrepancy.
- The source lists versions through v2.0.0-next.192 as affected and v2.0.0-next.193 as patched; it supplies no patch date or implementation detail.
- Reported removal could disrupt retrieval. Permanent erasure of underlying stored documents, production compromise and an award are not independently established.
- Conceptual defensive summary only; public disclosure grants no testing authorization.
Sources and provenance
- IDOR in Knowledge Base File Removal Allows Cross User File Deletion LobeHub · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.