open-webui/backend
Classic298 5e7244ab8b fix: gate OAuth profile picture MIME at ingestion + storage layer
Three defense-in-depth gaps from GHSA-3wgj-c2hg-vm6q that the v0.9.5
serving-side fix didn't address:

1. _process_picture_url (utils/oauth.py): MIME was inferred from the
   URL extension via mimetypes.guess_type, the upstream Content-Type
   was discarded, and there was no allowlist. An SVG picture URL
   produced data:image/svg+xml;base64,... in the user's
   profile_image_url. Switch to the upstream Content-Type and gate it
   against PROFILE_IMAGE_ALLOWED_MIME_TYPES (the same env var the
   serving endpoint already uses); fall back to /user.png if the MIME
   isn't in the allowlist. Also pass allow_redirects=AIOHTTP_CLIENT_
   ALLOW_REDIRECTS on the aiohttp session.get — the existing
   validate_url() only checks the initial URL, redirects to internal
   targets would otherwise still be followed (same class as the
   rh5x-h6pp-cjj6 cluster, sixth call site).

2. update_user_profile_image_url_by_id (models/users.py): SQLAlchemy
   write path bypassed the Pydantic form validators, so anything
   stored via OAuth or any other non-form caller landed in the column
   unchallenged. Run validate_profile_image_url at the storage layer
   before the assignment.

3. insert_new_user (models/users.py): same gap on the new-user path
   used by Auths.insert_new_auth (OAuth signup, LDAP). Same
   storage-layer call to validate_profile_image_url, falling back to
   /user.png if the supplied value doesn't pass.

The serving-endpoint allowlist landed in v0.9.5 already broke the
exploit chain matte1782 demonstrated (browser never receives
Content-Type: image/svg+xml), but bad data was still being written
to the DB and the upstream MIME was never trusted. These three
fixes harden the ingestion + storage layers so future serving paths
or DB readers don't have to assume the column is clean.

Reported by matte1782 in GHSA-3wgj-c2hg-vm6q.

Co-authored-by: matte1782 <matte1782@users.noreply.github.com>
2026-05-10 21:52:16 +02:00
..
data refac: mv backend files to /open_webui dir 2024-09-04 16:54:48 +02:00
open_webui fix: gate OAuth profile picture MIME at ingestion + storage layer 2026-05-10 21:52:16 +02:00
.dockerignore fix: litellm config issue 2024-02-24 22:35:11 -08:00
.gitignore refac 2024-09-06 04:59:20 +02:00
dev.sh refac 2026-03-24 19:43:30 -05:00
requirements-min.txt refac 2026-04-24 18:20:10 +09:00
requirements.txt refactor(firecrawl): use v2 API directly (#23934) 2026-04-24 18:32:08 +09:00
start.sh refac 2026-03-24 19:43:30 -05:00
start_windows.bat refac 2026-04-24 15:40:02 +09:00