Timothy Jaeryang Baek
2e71b3fbb8
chore: format
2026-05-09 21:07:08 +09:00
Timothy Jaeryang Baek
df42d96c95
refac
2026-05-09 21:05:49 +09:00
Timothy Jaeryang Baek
2fa3b84241
chore: bump
2026-05-09 21:04:52 +09:00
Classic298
8854541508
fix: prevent redirect-based SSRF in web-fetch and image-load call sites ( #24491 )
...
validate_url() in retrieval/web/utils.py only validates the initial URL.
The HTTP clients used downstream (sync requests, sync requests via the
parent WebBaseLoader._scrape, aiohttp via load_url_image) followed 3xx
redirects by default and did not re-validate the redirect target against
the private-IP / metadata-IP block list. An authenticated user could
submit a public URL that 302-redirected to an internal address (RFC1918,
127.0.0.1, 169.254.169.254, etc.) and the redirected response was returned
to them, enabling SSRF reads of internal services and cloud metadata.
Three call sites needed allow_redirects=False to match the policy already
enforced on the async _fetch() path:
- SafeWebBaseLoader: override requests_kwargs in __init__ so that the
inherited synchronous _scrape() path passes allow_redirects=False to
self.session.get() (the parent WebBaseLoader uses requests' default
allow_redirects=True).
- get_content_from_url (retrieval/utils.py): pass allow_redirects=False
on the streamed requests.get(...) call.
- load_url_image (routers/images.py, image-edits endpoint): pass
allow_redirects=False on the aiohttp session.get(...) call.
Reports consolidated under GHSA-rh5x-h6pp-cjj6:
- GHSA-rh5x-h6pp-cjj6 (tenbbughunters / Tenable) - sync _scrape
- GHSA-5vxg-6gmv-m2qr (YLChen-007) - load_url_image
- GHSA-hf76-c83f-63w2 (tempcollab) - aiohttp _fetch (already fixed)
- GHSA-h55f-h5fh-mvm4 (sneaXOR) - get_content_from_url
2026-05-09 21:01:45 +09:00
Timothy Jaeryang Baek
793e628ac3
refac
2026-05-09 20:59:29 +09:00
Classic298
a0268e51fc
Merge pull request #24486 from Classic298/fix/notes-is-pinned-typeerror
...
fix: notes is_pinned TypeError on create/get
2026-05-09 20:56:06 +09:00
Timothy Jaeryang Baek
0f07af1bb8
fix: bump to 0.9.4, changelog for scroll fix
2026-05-09 16:41:01 +09:00
Timothy Jaeryang Baek
7d3efb8513
refac
2026-05-09 16:37:19 +09:00
Timothy Jaeryang Baek
413dcae8a2
refac
2026-05-09 16:11:19 +09:00
Timothy Jaeryang Baek
d34d4297ba
chore: format
2026-05-09 16:08:22 +09:00
Timothy Jaeryang Baek
6116c6dca0
refac
2026-05-09 16:06:09 +09:00
Timothy Jaeryang Baek
93931efaa7
refac
2026-05-09 16:05:21 +09:00
Timothy Jaeryang Baek
3ccf263b10
refac
2026-05-09 15:46:33 +09:00
Timothy Jaeryang Baek
75e72ea2f9
doc: changelog
2026-05-09 15:41:58 +09:00
Classic298
b94aad2895
chore: changelog ( #24358 )
...
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
* changelog
2026-05-09 15:26:04 +09:00
Timothy Jaeryang Baek
7bcc0e2e5c
chore: format
2026-05-09 15:25:27 +09:00
Timothy Jaeryang Baek
46ff3abbb8
refac
2026-05-09 15:23:00 +09:00
Timothy Jaeryang Baek
aa51ce482c
refac
2026-05-09 15:21:31 +09:00
Timothy Jaeryang Baek
251b80ebec
refac
2026-05-09 15:14:32 +09:00
Timothy Jaeryang Baek
4d99baa292
refac
2026-05-09 15:04:09 +09:00
Timothy Jaeryang Baek
3fcad2f627
refac
2026-05-09 08:28:29 +09:00
Timothy Jaeryang Baek
04bd0425ea
refac
2026-05-09 07:56:58 +09:00
Timothy Jaeryang Baek
485d689cfd
refac
2026-05-09 07:52:15 +09:00
Timothy Jaeryang Baek
85c7373f68
refac
2026-05-09 07:37:53 +09:00
Timothy Jaeryang Baek
11e076817a
refac
2026-05-09 07:34:46 +09:00
Classic298
cfd2888545
fix:image url validation and signout post ( #24420 )
...
* refac(routers): reject external URLs in profile/model image handlers
* refac(ui): centralize image URL validation in safeImageUrl helper
* refac(auths): make signout POST-only
* refac: gate external profile image redirect behind ENABLE_PROFILE_IMAGE_URL_FORWARDING
Restore the 302 redirect for external http(s) profile image URLs in
the user and model profile-image endpoints, but gate it behind a new
ENABLE_PROFILE_IMAGE_URL_FORWARDING env flag (default: True).
Existing deployments that rely on external profile image forwarding
continue to work unchanged. Operators who want to suppress the
redirect (to prevent client-side IP/UA/Referer leaks) can set the
flag to False.
2026-05-09 07:33:31 +09:00
+5
adda20509c
fix(mcp): remove asyncio.wait_for/shield from MCP cleanup in chat handler ( #24105 )
...
asyncio.wait_for() and asyncio.shield() create new asyncio Tasks which
violate anyio cancel-scope task-ownership rules. The MCPClient's
exit_stack contains anyio resources (streamable_http transport) that
use anyio cancel scopes. When exited from a different task, anyio raises
'Attempted to exit a cancel scope that isn't the current task's current
cancel scope' as a BaseException.
This BaseException propagates through the finally block, discards the
completed response return value, and surfaces as a 500 Internal Server
Error / 'No response returned.' - silently swallowing successful MCP
tool calls and blocking the chat endpoint.
Fix: call client.disconnect() directly in a simple loop. MCPClient.disconnect()
already catches BaseException internally (see prior commit), so no
wrapper is needed.
Signed-off-by: Adam Tao <tcx4c70@gmail.com >
Co-authored-by: Tim Baek <tim@openwebui.com >
Co-authored-by: joaoback <156559121+joaoback@users.noreply.github.com >
Co-authored-by: Algorithm5838 <108630393+Algorithm5838@users.noreply.github.com >
Co-authored-by: Kylapaallikko <Kylapaallikko@users.noreply.github.com >
Co-authored-by: Teay <pythontogoplease@gmail.com >
Co-authored-by: tcx4c70 <tcx4c70@gmail.com >
Co-authored-by: goodbey857 <76645482+goodbey857@users.noreply.github.com >
Co-authored-by: Jacob Leksan <63938553+jmleksan@users.noreply.github.com >
Co-authored-by: RomualdYT <romuald@gameurnews.fr >
Co-authored-by: Lucas <lucas@vanosenbruggen.com >
Co-authored-by: Classic298 <27028174+Classic298@users.noreply.github.com >
Co-authored-by: Constantine <Runixer@gmail.com >
Co-authored-by: Circe (Claude Code Sonnet 4.6) <circe@athena-council.org >
Co-authored-by: Claude <noreply@anthropic.com >
2026-05-09 07:15:24 +09:00
Timothy Jaeryang Baek
e1dce99147
refac
2026-05-09 07:13:36 +09:00
Timothy Jaeryang Baek
a938c8ae2e
refac
2026-05-09 07:11:17 +09:00
Timothy Jaeryang Baek
5b80932e59
refac
2026-05-09 06:56:22 +09:00
Timothy Jaeryang Baek
2ba6b423aa
refac
2026-05-09 06:50:11 +09:00
Timothy Jaeryang Baek
02f9fe7890
refac
2026-05-09 06:49:41 +09:00
Timothy Jaeryang Baek
29f6c72e87
refac
2026-05-09 06:44:42 +09:00
Timothy Jaeryang Baek
bb0e6cb108
refac
2026-05-09 06:41:42 +09:00
Timothy Jaeryang Baek
6700f7bb72
feat: brave search llm context
2026-05-09 06:34:25 +09:00
Timothy Jaeryang Baek
1baf73bdd5
refac
2026-05-09 06:34:03 +09:00
Timothy Jaeryang Baek
1d892ce2c5
refac
2026-05-09 06:33:26 +09:00
Timothy Jaeryang Baek
794b97025d
refac
2026-05-09 06:32:34 +09:00
Timothy Jaeryang Baek
ee3b82926b
refac
2026-05-09 06:25:38 +09:00
Timothy Jaeryang Baek
38a382ef88
refac
2026-05-09 06:23:51 +09:00
Timothy Jaeryang Baek
34146ab60f
refac
2026-05-09 06:20:27 +09:00
Timothy Jaeryang Baek
f70b0da156
refac
2026-05-09 06:16:27 +09:00
Timothy Jaeryang Baek
af5628f8ef
refac
2026-05-09 06:13:58 +09:00
Timothy Jaeryang Baek
9907c0a25a
refac
2026-05-09 06:01:02 +09:00
+3
d78c247036
Korean Translation Update ( #24087 )
...
Signed-off-by: Adam Tao <tcx4c70@gmail.com >
Co-authored-by: Tim Baek <tim@openwebui.com >
Co-authored-by: joaoback <156559121+joaoback@users.noreply.github.com >
Co-authored-by: Algorithm5838 <108630393+Algorithm5838@users.noreply.github.com >
Co-authored-by: Kylapaallikko <Kylapaallikko@users.noreply.github.com >
Co-authored-by: Teay <pythontogoplease@gmail.com >
Co-authored-by: tcx4c70 <tcx4c70@gmail.com >
Co-authored-by: goodbey857 <76645482+goodbey857@users.noreply.github.com >
Co-authored-by: Jacob Leksan <63938553+jmleksan@users.noreply.github.com >
Co-authored-by: RomualdYT <romuald@gameurnews.fr >
Co-authored-by: Lucas <lucas@vanosenbruggen.com >
Co-authored-by: Classic298 <27028174+Classic298@users.noreply.github.com >
Co-authored-by: Constantine <Runixer@gmail.com >
2026-05-09 05:31:49 +09:00
Shamil
ae0827cec0
style(env): satisfy ruff (datetime alias, line length, identity check) ( #24118 )
2026-05-09 05:30:09 +09:00
Timothy Jaeryang Baek
064fdecb67
refac
2026-05-09 05:29:15 +09:00
Timothy Jaeryang Baek
bf4f44ee9c
refac
2026-05-09 05:27:47 +09:00
Timothy Jaeryang Baek
212bb68a66
refac
2026-05-09 05:27:32 +09:00
+3
aff78e4958
i18n: Add Tagalog (Filipino) translation ( #24254 )
...
Signed-off-by: Adam Tao <tcx4c70@gmail.com >
Co-authored-by: Tim Baek <tim@openwebui.com >
Co-authored-by: joaoback <156559121+joaoback@users.noreply.github.com >
Co-authored-by: Algorithm5838 <108630393+Algorithm5838@users.noreply.github.com >
Co-authored-by: Kylapaallikko <Kylapaallikko@users.noreply.github.com >
Co-authored-by: Teay <pythontogoplease@gmail.com >
Co-authored-by: tcx4c70 <tcx4c70@gmail.com >
Co-authored-by: goodbey857 <76645482+goodbey857@users.noreply.github.com >
Co-authored-by: Jacob Leksan <63938553+jmleksan@users.noreply.github.com >
Co-authored-by: RomualdYT <romuald@gameurnews.fr >
Co-authored-by: Lucas <lucas@vanosenbruggen.com >
Co-authored-by: Classic298 <27028174+Classic298@users.noreply.github.com >
Co-authored-by: Constantine <Runixer@gmail.com >
2026-05-09 05:25:44 +09:00