mirror of
https://github.com/open-webui/open-webui.git
synced 2026-05-07 11:28:35 -05:00
[PR #18961] [CLOSED] Fix SSRF vulnerability in web fetch endpoint (GHSA-c6xv-rcvw-v685) #25034
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
📋 Pull Request Information
Original PR: https://github.com/open-webui/open-webui/pull/18961
Author: @teolines
Created: 11/6/2025
Status: ❌ Closed
Base:
main← Head:fix/ssrf-ghsa-c6xv-rcvw-v685📝 Commits (1)
1235ca8Fix SSRF vulnerability in web fetch endpoint (GHSA-c6xv-rcvw-v685)📊 Changes
4 files changed (+284 additions, -0 deletions)
View changed files
📝
backend/open_webui/config.py(+19 -0)📝
backend/open_webui/main.py(+6 -0)➕
backend/open_webui/retrieval/ssrf_protection.py(+207 -0)📝
backend/open_webui/routers/retrieval.py(+52 -0)📄 Description
Security: Fixes GHSA-c6xv-rcvw-v685 (CWE-918)
Reported-by: @teorepo
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.