open-webui/backend/open_webui/routers
Classic298 5f3a628a8d
Encode terminal ws session_id to block upstream user_id query injection (#26042)
ws_terminal() interpolated the path parameter session_id directly into the upstream
terminal WebSocket URL and then appended ?user_id=<caller>, with no encoding or
validation (the HTTP sibling proxy_terminal runs _sanitize_proxy_path; this path ran
nothing). An encoded '?'/'&' smuggled through session_id survives Open WebUI's single
decode and is re-decoded by the upstream, injecting an attacker-chosen user_id ahead
of the appended one. Query parsing binds the first occurrence, so the orchestrator
resolves the spoofed user's terminal scope, letting a normal authenticated user
present another user's identity to the upstream (CWE-116/863).

Encode session_id as an opaque path segment with urllib.parse.quote(session_id,
safe=''). This neutralises '?'/'#'/'&' at any decode depth (the upstream's single
decode reverses only the quote, leaving the original delimiters inert as path
content), while legitimate UUID session ids pass through unchanged. The appended
user_id is then the only query parameter the upstream binds.

The separate concern that the forwarded identity is a bearer claim with no integrity
binding spans Open WebUI and the upstream terminal server and is not addressed here.

Co-authored-by: rexpository <30176934+rexpository@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-17 00:15:39 +02:00
..
analytics.py refac 2026-06-16 23:24:27 +02:00
audio.py refac 2026-06-16 23:30:24 +02:00
auths.py fix(auth): enforce features.api_keys permission on GET and DELETE /api_key endpoints (#25992) 2026-06-16 22:48:44 +02:00
automations.py refac: modernize type annotations (PEP 604 / PEP 585) 2026-05-12 17:10:15 +09:00
calendar.py fix: check destination calendar write access on event update (#24764) 2026-05-19 21:26:58 +04:00
channels.py refac 2026-06-16 23:59:24 +02:00
chats.py refac 2026-06-15 23:34:24 +02:00
configs.py refac: modernize type annotations (PEP 604 / PEP 585) 2026-05-12 17:10:15 +09:00
evaluations.py refac 2026-06-01 13:20:33 -07:00
files.py Authorize KB write access before auto-linking an uploaded file (CWE-862/863) (#26001) 2026-06-16 22:56:24 +02:00
folders.py refac 2026-06-16 22:53:57 +02:00
functions.py refac: modernize type annotations (PEP 604 / PEP 585) 2026-05-12 17:10:15 +09:00
groups.py chore: format 2026-06-01 13:56:55 -07:00
images.py Route user-supplied image-URL fetches through an SSRF-safe session (DNS rebinding, CWE-918) (#25960) 2026-06-16 23:36:53 +02:00
knowledge.py chore: format 2026-06-01 13:56:55 -07:00
memories.py chore: format 2026-06-01 13:56:55 -07:00
models.py Fail closed when the proxy/redirect path decode cap is exceeded (#26050) 2026-06-16 22:44:11 +02:00
notes.py refac: modernize type annotations (PEP 604 / PEP 585) 2026-05-12 17:10:15 +09:00
ollama.py chore: format 2026-06-01 13:56:55 -07:00
openai.py fix(auth): enforce chat.tts permission on OpenAI /audio/speech proxy endpoint (#25993) 2026-06-16 22:54:35 +02:00
pipelines.py refac: modernize type annotations (PEP 604 / PEP 585) 2026-05-12 17:10:15 +09:00
prompts.py chore: format 2026-06-01 13:56:55 -07:00
retrieval.py chore: format 2026-06-01 13:56:55 -07:00
scim.py Don't let SCIM's active flag demote an admin (defense-in-depth) (#25948) 2026-06-16 23:59:55 +02:00
skills.py refac: modernize type annotations (PEP 604 / PEP 585) 2026-05-12 17:10:15 +09:00
tasks.py refac 2026-05-14 13:19:00 +09:00
terminals.py Encode terminal ws session_id to block upstream user_id query injection (#26042) 2026-06-17 00:15:39 +02:00
tools.py chore: format 2026-06-01 13:56:55 -07:00
users.py chore: format 2026-06-01 13:56:55 -07:00
utils.py refac 2026-05-21 16:25:25 +04:00