open-webui/backend/open_webui
Classic298 5e7244ab8b fix: gate OAuth profile picture MIME at ingestion + storage layer
Three defense-in-depth gaps from GHSA-3wgj-c2hg-vm6q that the v0.9.5
serving-side fix didn't address:

1. _process_picture_url (utils/oauth.py): MIME was inferred from the
   URL extension via mimetypes.guess_type, the upstream Content-Type
   was discarded, and there was no allowlist. An SVG picture URL
   produced data:image/svg+xml;base64,... in the user's
   profile_image_url. Switch to the upstream Content-Type and gate it
   against PROFILE_IMAGE_ALLOWED_MIME_TYPES (the same env var the
   serving endpoint already uses); fall back to /user.png if the MIME
   isn't in the allowlist. Also pass allow_redirects=AIOHTTP_CLIENT_
   ALLOW_REDIRECTS on the aiohttp session.get — the existing
   validate_url() only checks the initial URL, redirects to internal
   targets would otherwise still be followed (same class as the
   rh5x-h6pp-cjj6 cluster, sixth call site).

2. update_user_profile_image_url_by_id (models/users.py): SQLAlchemy
   write path bypassed the Pydantic form validators, so anything
   stored via OAuth or any other non-form caller landed in the column
   unchallenged. Run validate_profile_image_url at the storage layer
   before the assignment.

3. insert_new_user (models/users.py): same gap on the new-user path
   used by Auths.insert_new_auth (OAuth signup, LDAP). Same
   storage-layer call to validate_profile_image_url, falling back to
   /user.png if the supplied value doesn't pass.

The serving-endpoint allowlist landed in v0.9.5 already broke the
exploit chain matte1782 demonstrated (browser never receives
Content-Type: image/svg+xml), but bad data was still being written
to the DB and the upstream MIME was never trusted. These three
fixes harden the ingestion + storage layers so future serving paths
or DB readers don't have to assume the column is clean.

Reported by matte1782 in GHSA-3wgj-c2hg-vm6q.

Co-authored-by: matte1782 <matte1782@users.noreply.github.com>
2026-05-10 21:52:16 +02:00
..
data refac: mv backend files to /open_webui dir 2024-09-04 16:54:48 +02:00
internal chore: format 2026-05-09 15:25:27 +09:00
migrations chore: format 2026-05-09 15:25:27 +09:00
models fix: gate OAuth profile picture MIME at ingestion + storage layer 2026-05-10 21:52:16 +02:00
retrieval fix: reject parser-confusing chars in validate_url to close SSRF bypass (#24534) 2026-05-11 00:57:48 +09:00
routers refac 2026-05-11 03:30:12 +09:00
socket chore: format 2026-05-11 02:51:59 +09:00
static chore: format 2026-04-19 22:45:54 +09:00
storage refac 2026-04-12 19:08:30 -05:00
test refac 2026-03-17 17:58:01 -05:00
tools chore: format 2026-05-09 15:25:27 +09:00
utils fix: gate OAuth profile picture MIME at ingestion + storage layer 2026-05-10 21:52:16 +02:00
__init__.py refac 2026-05-09 02:38:08 +09:00
alembic.ini fix: Alembic CLI commands from failing 2025-08-15 04:17:47 -04:00
config.py feat: add IFRAME_CSP env var for srcdoc iframe content security policy 2026-05-11 01:56:02 +09:00
constants.py chore: format 2026-04-14 17:27:31 -05:00
env.py refac 2026-05-11 02:25:11 +09:00
functions.py refac 2026-05-09 04:17:58 +09:00
main.py chore: format 2026-05-11 02:51:59 +09:00
tasks.py refac 2026-03-17 17:58:01 -05:00