profile_image_url is an injection vulnerability #947

Closed
opened 2025-11-11 14:34:08 -06:00 by GiteaMirror · 0 comments
Owner

Originally created by @qrdlgit on GitHub (May 17, 2024).

I reported this as a security issue but it was ignored, so I am reporting it here. A user can signup with their own profile image url and there are no checks done on this and rendered on the front end as is. It can be used to track ip addresses, set tracking cookies, xss on older web browsers, do internal get references on private ips, etc.

Originally created by @qrdlgit on GitHub (May 17, 2024). I reported this as a security issue but it was ignored, so I am reporting it here. A user can signup with their own profile image url and there are no checks done on this and rendered on the front end as is. It can be used to track ip addresses, set tracking cookies, xss on older web browsers, do internal get references on private ips, etc.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/open-webui#947