Files
open-webui/backend/open_webui
f5f4b58958 fix: harden model profile image against SVG stored XSS (#25060)
ModelMeta.profile_image_url now runs validate_profile_image_url, rejecting SVG/script data URIs (matching UserUpdateForm and ChannelWebhookForm). The /model/profile/image endpoint enforces the PROFILE_IMAGE_ALLOWED_MIME_TYPES allowlist and sets X-Content-Type-Options: nosniff, so an SVG data URI can no longer be served inline on-origin. Closes the fourth profile-image XSS sink missed by the user and webhook fixes.

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-28 17:41:55 -05:00
..
2026-05-21 16:25:25 +04:00
2026-05-21 15:29:49 +04:00
2026-05-21 16:44:36 +04:00
2026-05-12 03:04:35 +09:00
2026-05-09 02:38:08 +09:00
2026-05-21 16:56:56 +04:00
2026-05-20 00:22:27 +04:00
2026-05-21 16:56:56 +04:00