mirror of
https://github.com/open-webui/open-webui.git
synced 2026-05-06 10:58:17 -05:00
[PR #14328] [MERGED] fix: Fix path leakage caused by file upload #23445
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
📋 Pull Request Information
Original PR: https://github.com/open-webui/open-webui/pull/14328
Author: @ShirasawaSama
Created: 5/26/2025
Status: ✅ Merged
Merged: 5/26/2025
Merged by: @tjbck
Base:
main← Head:fix_path_leakage_caused_by_file_upload📝 Commits (1)
0dc29a2fix: Fix path leakage caused by file upload📊 Changes
1 file changed (+1 additions, -1 deletions)
View changed files
📝
backend/open_webui/routers/files.py(+1 -1)📄 Description
Pull Request Checklist
Note to first-time contributors: Please open a discussion post in Discussions and describe your changes before submitting a pull request.
Before submitting, make sure you've checked the following:
devbranch.Changelog Entry
Description
We can construct a very long filename such as
(a*50000).txtto trigger the exception catching branch https://github.com/open-webui/open-webui/blob/main/backend/open_webui/routers/files.py#L192 .The exception will then contain the absolute path to the file to be saved:
Added
Changed
Deprecated
Removed
Fixed
Security
backend/open_webui/routers/files.py: Instead of outputting the python error message directly, we should filter it and then output it.Breaking Changes
Additional Information
Screenshots or Videos
Contributor License Agreement
By submitting this pull request, I confirm that I have read and fully agree to the Contributor License Agreement (CLA), and I am providing my contributions under its terms.
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.