mirror of
https://github.com/open-webui/open-webui.git
synced 2026-05-06 19:08:59 -05:00
[PR #13868] [CLOSED] fix: Arbitrary code file deletion vulnerability of /pipelines/upload #23316
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
📋 Pull Request Information
Original PR: https://github.com/open-webui/open-webui/pull/13868
Author: @ShirasawaSama
Created: 5/14/2025
Status: ❌ Closed
Base:
dev← Head:fix_pipelines_upload_arbitrary_file_deletion_vulnerability📝 Commits (1)
8a262bffix: Arbitrary code file deletion vulnerability of pipelines upload📊 Changes
1 file changed (+38 additions, -35 deletions)
View changed files
📝
backend/open_webui/routers/pipelines.py(+38 -35)📄 Description
Pull Request Checklist
Note to first-time contributors: Please open a discussion post in Discussions and describe your changes before submitting a pull request.
Before submitting, make sure you've checked the following:
devbranch.Changelog Entry
Description
When the user constructs a file name similar to './../../../open_webui/backend/main.py', the deletion of any backend py file can be completed.
Added
N/A
Changed
N/A
Deprecated
N/A
Removed
N/A
Fixed
N/A
Security
backend/open_webui/routers/pipelines.py: Refactoring the logic of the upload_pipeline function to avoid direct reading and writing of hard disk files.Breaking Changes
N/A
Additional Information
This line of code did not filter relative file paths, resulting in security issues: https://github.com/open-webui/open-webui/blob/main/backend/open_webui/routers/pipelines.py#L254
Screenshots or Videos
Contributor License Agreement
By submitting this pull request, I confirm that I have read and fully agree to the Contributor License Agreement (CLA), and I am providing my contributions under its terms.
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.