mirror of
https://github.com/open-webui/open-webui.git
synced 2026-09-15 23:32:40 +00:00
is_string_allowed does endswith() matching and was called with the full URL (retrieval/web/utils.py) against WEB_FETCH_FILTER_LIST, so a blocklisted host with any path (https://blocked.example/x) ended with /x, not the host, and slipped through; the allowlist direction false-rejected legitimate URLs and admitted attacker URLs ending in an allowed string. The same endswith caused label confusion at the hostname call site (retrieval/web/main.py): corp.com matched evilcorp.com, 10.0.0.1 matched 110.0.0.1. Add is_host_allowed(host, ...) matching on DNS label boundaries (host == pattern or host.endswith('.' + pattern)), called with the parsed hostname at both web-fetch call sites. is_string_allowed is left unchanged for the unrelated function-name filters (utils/middleware.py, utils/tools.py). The separate is_global guard (validate_url / _ssrf_safe_new_conn, active when ENABLE_RAG_LOCAL_WEB_FETCH is off) already blocks RFC1918/loopback/link-local, so this restores the admin's intended blocking of specific public hosts. Co-authored-by: addcontent <59762500+addcontent@users.noreply.github.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| azure.py | ||
| bing.py | ||
| bocha.py | ||
| brave.py | ||
| brave_llm_context.py | ||
| duckduckgo.py | ||
| exa.py | ||
| external.py | ||
| firecrawl.py | ||
| google_pse.py | ||
| jina_search.py | ||
| kagi.py | ||
| linkup.py | ||
| main.py | ||
| mojeek.py | ||
| ollama.py | ||
| perplexity.py | ||
| perplexity_search.py | ||
| searchapi.py | ||
| searxng.py | ||
| serpapi.py | ||
| serper.py | ||
| serply.py | ||
| serpstack.py | ||
| sougou.py | ||
| tavily.py | ||
| utils.py | ||
| yacy.py | ||
| yandex.py | ||
| ydc.py | ||