Files
open-webui/backend/open_webui/models
Classic298andClaude Opus 4.7 f5f4b58958 fix: harden model profile image against SVG stored XSS (#25060)
ModelMeta.profile_image_url now runs validate_profile_image_url, rejecting SVG/script data URIs (matching UserUpdateForm and ChannelWebhookForm). The /model/profile/image endpoint enforces the PROFILE_IMAGE_ALLOWED_MIME_TYPES allowlist and sets X-Content-Type-Options: nosniff, so an SVG data URI can no longer be served inline on-origin. Closes the fourth profile-image XSS sink missed by the user and webhook fixes.

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-28 17:41:55 -05:00
..
2026-05-21 15:29:49 +04:00
2026-05-19 20:37:53 +04:00
2026-05-21 17:48:28 +04:00
2026-05-21 15:29:49 +04:00
2026-05-21 15:29:49 +04:00
2026-05-28 17:24:33 -05:00
2026-05-21 15:29:49 +04:00
2026-05-14 01:49:34 +09:00
2026-05-21 15:29:49 +04:00
2026-05-21 15:29:49 +04:00
2026-05-21 15:29:49 +04:00