mirror of
https://github.com/open-webui/open-webui.git
synced 2026-10-10 03:27:57 +00:00
validate_url() in retrieval/web/utils.py only validates the initial URL. The HTTP clients used downstream (sync requests, sync requests via the parent WebBaseLoader._scrape, aiohttp via load_url_image) followed 3xx redirects by default and did not re-validate the redirect target against the private-IP / metadata-IP block list. An authenticated user could submit a public URL that 302-redirected to an internal address (RFC1918, 127.0.0.1, 169.254.169.254, etc.) and the redirected response was returned to them, enabling SSRF reads of internal services and cloud metadata. Three call sites needed allow_redirects=False to match the policy already enforced on the async _fetch() path: - SafeWebBaseLoader: override requests_kwargs in __init__ so that the inherited synchronous _scrape() path passes allow_redirects=False to self.session.get() (the parent WebBaseLoader uses requests' default allow_redirects=True). - get_content_from_url (retrieval/utils.py): pass allow_redirects=False on the streamed requests.get(...) call. - load_url_image (routers/images.py, image-edits endpoint): pass allow_redirects=False on the aiohttp session.get(...) call. Reports consolidated under GHSA-rh5x-h6pp-cjj6: - GHSA-rh5x-h6pp-cjj6 (tenbbughunters / Tenable) - sync _scrape - GHSA-5vxg-6gmv-m2qr (YLChen-007) - load_url_image - GHSA-hf76-c83f-63w2 (tempcollab) - aiohttp _fetch (already fixed) - GHSA-h55f-h5fh-mvm4 (sneaXOR) - get_content_from_url |
||
|---|---|---|
| .. | ||
| data | ||
| internal | ||
| migrations | ||
| models | ||
| retrieval | ||
| routers | ||
| socket | ||
| static | ||
| storage | ||
| test | ||
| tools | ||
| utils | ||
| __init__.py | ||
| alembic.ini | ||
| config.py | ||
| constants.py | ||
| env.py | ||
| functions.py | ||
| main.py | ||
| tasks.py | ||