Files
open-webui/backend/open_webui/routers
Classic298andClaude Opus 4.7 f5f4b58958 fix: harden model profile image against SVG stored XSS (#25060)
ModelMeta.profile_image_url now runs validate_profile_image_url, rejecting SVG/script data URIs (matching UserUpdateForm and ChannelWebhookForm). The /model/profile/image endpoint enforces the PROFILE_IMAGE_ALLOWED_MIME_TYPES allowlist and sets X-Content-Type-Options: nosniff, so an SVG data URI can no longer be served inline on-origin. Closes the fourth profile-image XSS sink missed by the user and webhook fixes.

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-28 17:41:55 -05:00
..
2026-05-21 18:43:45 +04:00
2026-05-21 16:56:56 +04:00
2026-05-19 20:44:38 +04:00
2026-05-21 16:56:56 +04:00
2026-05-20 01:30:26 +04:00
2026-05-14 13:12:59 +09:00
2026-05-14 02:40:20 +09:00
2026-05-28 17:24:33 -05:00
2026-05-21 14:01:57 +04:00
2026-05-25 20:15:03 +04:00
2026-05-20 00:26:22 +04:00
2026-05-21 14:01:57 +04:00
2026-05-21 16:56:56 +04:00
2026-05-14 13:19:00 +09:00
2026-05-21 14:01:57 +04:00
2026-05-21 15:29:49 +04:00
2026-05-21 16:25:25 +04:00