From b4ebd0d62fccd902484e861015ef9fc384987338 Mon Sep 17 00:00:00 2001 From: Classic298 <27028174+Classic298@users.noreply.github.com> Date: Wed, 30 Sep 2026 17:08:48 +0200 Subject: [PATCH] refac(hardening): apply the same safety checks to generated image downloads (#31623) When an image generation backend returns a link instead of the image itself, the download now goes through the same safety checks used for other external image downloads. Links on the configured ComfyUI address are still trusted as before, so a ComfyUI server on a local network keeps working. --- backend/open_webui/routers/images.py | 17 +++++++++++------ 1 file changed, 11 insertions(+), 6 deletions(-) diff --git a/backend/open_webui/routers/images.py b/backend/open_webui/routers/images.py index c894f2c651..28a037a993 100644 --- a/backend/open_webui/routers/images.py +++ b/backend/open_webui/routers/images.py @@ -7,6 +7,7 @@ import logging import mimetypes import re import uuid +from contextlib import nullcontext from pathlib import Path from types import SimpleNamespace from typing import Optional @@ -488,14 +489,18 @@ async def get_image_data(data: str, headers=None, trusted_base_url: str | None = # that would follow arbitrary redirects. if trusted_base_url and _is_same_origin(data, trusted_base_url): log.debug('Skipping URL validation for trusted backend: %s', data) + session_context = nullcontext(await get_session()) else: await asyncio.to_thread(validate_url, data) - session = await get_session() - async with session.get( - data, - headers=headers, - ssl=AIOHTTP_CLIENT_SESSION_SSL, - ) as r: + session_context = get_ssrf_safe_session() + async with ( + session_context as session, + session.get( + data, + headers=headers, + ssl=AIOHTTP_CLIENT_SESSION_SSL, + ) as r, + ): r.raise_for_status() content_type = r.headers.get('content-type', '') if content_type.split('/')[0] == 'image':