2024-03-26 15:04:17 +08:00
|
|
|
import json
|
2024-03-31 13:17:29 -06:00
|
|
|
import logging
|
|
|
|
|
|
2026-05-12 17:10:15 +09:00
|
|
|
import aiohttp
|
2025-02-16 00:11:18 -08:00
|
|
|
from open_webui.config import WEBUI_FAVICON_URL
|
fix: block private-IP webhook URLs to close SSRF on caller-controlled URL (#24587)
* fix: block private-IP webhook URLs to close SSRF on caller-controlled URL
post_webhook(url, ...) in utils/webhook.py forwards the URL straight to
aiohttp.ClientSession.post with no SSRF gate. The URL is caller-controlled
on two surfaces:
- User notification settings under ENABLE_USER_WEBHOOKS=true — any
authenticated user can set the URL their notifications POST to.
- Automation notification triggers (calendar alerts, etc.).
Without a gate, the URL can target cloud metadata (169.254.169.254 /
fd00:ec2::254), localhost-bound services, RFC1918 internal hosts, or any
other private address reachable from the server process. Blind SSRF — no
response body returned to the caller — but enough to enumerate internal
services via response timing / status codes, and on cloud deployments
enough to issue requests against IMDSv1 if available.
Call validate_url() at the top of post_webhook. The function blocks
private/reserved IPs when ENABLE_RAG_LOCAL_WEB_FETCH is False (the
default), is the project's chosen SSRF gate, and is already applied to
the equivalent fetch surfaces (retrieval, image-load, OAuth profile
picture). Operators who legitimately need to webhook to private IPs
(internal monitoring, self-hosted Slack alternatives, etc.) can set
ENABLE_RAG_LOCAL_WEB_FETCH=True — same opt-out as the other gated
surfaces.
Scope intentionally limited to webhooks. The OAuth discovery and
external reranker paths cwanglab also flagged are admin-configured with
intentional private-IP defaults (reranker defaults to
http://localhost:8080/v1/rerank) and are out of scope per Rule 9 — the
admin owns the URL choice and the operator opt-out exists for them too.
Reported by cwanglab in GHSA-5x9f-85cg-w3hf (cluster canonical with six
closed siblings: g36v-23gj-j69x, 6j8f-h58v-xgmw, xpwv-52pm-p8hj,
v9gp-hv2c-9qv8, fw7w-jrw7-p3v9, x7xq-74rg-m8mf).
Co-authored-by: cwanglab <cwanglab@users.noreply.github.com>
* fix: also pass allow_redirects=False on webhook post_webhook session.post
Companion to the previous commit. validate_url() only validates the
initial URL; aiohttp's default allow_redirects=True would still follow
a 302 to a private-IP target. Same redirect-bypass class as the rh5x
cluster's five call sites, sixth call site to receive the same gate.
Co-authored-by: cwanglab <cwanglab@users.noreply.github.com>
---------
Co-authored-by: cwanglab <cwanglab@users.noreply.github.com>
2026-06-01 23:15:51 +02:00
|
|
|
from open_webui.env import (
|
|
|
|
|
AIOHTTP_CLIENT_ALLOW_REDIRECTS,
|
|
|
|
|
AIOHTTP_CLIENT_SESSION_SSL,
|
|
|
|
|
AIOHTTP_CLIENT_TIMEOUT,
|
|
|
|
|
VERSION,
|
|
|
|
|
)
|
|
|
|
|
from open_webui.retrieval.web.utils import validate_url
|
2024-03-31 13:17:29 -06:00
|
|
|
|
|
|
|
|
log = logging.getLogger(__name__)
|
2024-03-20 18:35:02 -07:00
|
|
|
|
2024-03-31 01:13:39 -07:00
|
|
|
|
2026-03-24 04:49:48 -05:00
|
|
|
# Let this message reach those for whom it was written, and
|
|
|
|
|
# may no network partition deny the word its destination.
|
2025-08-15 00:07:02 +04:00
|
|
|
async def post_webhook(name: str, url: str, message: str, event_data: dict) -> bool:
|
2024-03-20 18:35:02 -07:00
|
|
|
try:
|
2026-03-17 17:58:01 -05:00
|
|
|
log.debug(f'post_webhook: {url}, {message}, {event_data}')
|
fix: block private-IP webhook URLs to close SSRF on caller-controlled URL (#24587)
* fix: block private-IP webhook URLs to close SSRF on caller-controlled URL
post_webhook(url, ...) in utils/webhook.py forwards the URL straight to
aiohttp.ClientSession.post with no SSRF gate. The URL is caller-controlled
on two surfaces:
- User notification settings under ENABLE_USER_WEBHOOKS=true — any
authenticated user can set the URL their notifications POST to.
- Automation notification triggers (calendar alerts, etc.).
Without a gate, the URL can target cloud metadata (169.254.169.254 /
fd00:ec2::254), localhost-bound services, RFC1918 internal hosts, or any
other private address reachable from the server process. Blind SSRF — no
response body returned to the caller — but enough to enumerate internal
services via response timing / status codes, and on cloud deployments
enough to issue requests against IMDSv1 if available.
Call validate_url() at the top of post_webhook. The function blocks
private/reserved IPs when ENABLE_RAG_LOCAL_WEB_FETCH is False (the
default), is the project's chosen SSRF gate, and is already applied to
the equivalent fetch surfaces (retrieval, image-load, OAuth profile
picture). Operators who legitimately need to webhook to private IPs
(internal monitoring, self-hosted Slack alternatives, etc.) can set
ENABLE_RAG_LOCAL_WEB_FETCH=True — same opt-out as the other gated
surfaces.
Scope intentionally limited to webhooks. The OAuth discovery and
external reranker paths cwanglab also flagged are admin-configured with
intentional private-IP defaults (reranker defaults to
http://localhost:8080/v1/rerank) and are out of scope per Rule 9 — the
admin owns the URL choice and the operator opt-out exists for them too.
Reported by cwanglab in GHSA-5x9f-85cg-w3hf (cluster canonical with six
closed siblings: g36v-23gj-j69x, 6j8f-h58v-xgmw, xpwv-52pm-p8hj,
v9gp-hv2c-9qv8, fw7w-jrw7-p3v9, x7xq-74rg-m8mf).
Co-authored-by: cwanglab <cwanglab@users.noreply.github.com>
* fix: also pass allow_redirects=False on webhook post_webhook session.post
Companion to the previous commit. validate_url() only validates the
initial URL; aiohttp's default allow_redirects=True would still follow
a 302 to a private-IP target. Same redirect-bypass class as the rh5x
cluster's five call sites, sixth call site to receive the same gate.
Co-authored-by: cwanglab <cwanglab@users.noreply.github.com>
---------
Co-authored-by: cwanglab <cwanglab@users.noreply.github.com>
2026-06-01 23:15:51 +02:00
|
|
|
# Block private-IP / loopback / cloud-metadata targets — the URL is
|
|
|
|
|
# caller-controlled (user notification settings under
|
|
|
|
|
# ENABLE_USER_WEBHOOKS, automation notification triggers).
|
|
|
|
|
validate_url(url)
|
2024-03-20 18:47:13 -07:00
|
|
|
payload = {}
|
|
|
|
|
|
2024-03-27 10:25:57 +08:00
|
|
|
# Slack and Google Chat Webhooks
|
2026-03-17 17:58:01 -05:00
|
|
|
if 'https://hooks.slack.com' in url or 'https://chat.googleapis.com' in url:
|
|
|
|
|
payload['text'] = message
|
2024-03-27 10:25:57 +08:00
|
|
|
# Discord Webhooks
|
2026-03-17 17:58:01 -05:00
|
|
|
elif 'https://discord.com/api/webhooks' in url:
|
|
|
|
|
payload['content'] = message if len(message) < 2000 else f'{message[: 2000 - 20]}... (truncated)'
|
2024-03-27 10:25:57 +08:00
|
|
|
# Microsoft Teams Webhooks
|
2026-03-17 17:58:01 -05:00
|
|
|
elif 'webhook.office.com' in url:
|
|
|
|
|
action = event_data.get('action', 'undefined')
|
|
|
|
|
user_data = event_data.get('user', '{}')
|
2026-03-09 05:45:21 +08:00
|
|
|
if isinstance(user_data, dict):
|
|
|
|
|
user_dict = user_data
|
|
|
|
|
else:
|
|
|
|
|
user_dict = json.loads(user_data)
|
2026-03-17 17:58:01 -05:00
|
|
|
facts = [{'name': name, 'value': value} for name, value in user_dict.items()]
|
2024-03-26 15:04:17 +08:00
|
|
|
payload = {
|
2026-03-17 17:58:01 -05:00
|
|
|
'@type': 'MessageCard',
|
|
|
|
|
'@context': 'http://schema.org/extensions',
|
|
|
|
|
'themeColor': '0076D7',
|
|
|
|
|
'summary': message,
|
|
|
|
|
'sections': [
|
2024-03-26 15:04:17 +08:00
|
|
|
{
|
2026-03-17 17:58:01 -05:00
|
|
|
'activityTitle': message,
|
|
|
|
|
'activitySubtitle': f'{name} ({VERSION}) - {action}',
|
|
|
|
|
'activityImage': WEBUI_FAVICON_URL,
|
|
|
|
|
'facts': facts,
|
|
|
|
|
'markdown': True,
|
2024-03-26 15:04:17 +08:00
|
|
|
}
|
|
|
|
|
],
|
|
|
|
|
}
|
2024-03-27 10:25:57 +08:00
|
|
|
# Default Payload
|
2024-03-20 18:47:13 -07:00
|
|
|
else:
|
|
|
|
|
payload = {**event_data}
|
|
|
|
|
|
2026-03-17 17:58:01 -05:00
|
|
|
log.debug(f'payload: {payload}')
|
2026-01-08 00:42:29 +04:00
|
|
|
async with aiohttp.ClientSession(
|
|
|
|
|
trust_env=True, timeout=aiohttp.ClientTimeout(total=AIOHTTP_CLIENT_TIMEOUT)
|
|
|
|
|
) as session:
|
fix: block private-IP webhook URLs to close SSRF on caller-controlled URL (#24587)
* fix: block private-IP webhook URLs to close SSRF on caller-controlled URL
post_webhook(url, ...) in utils/webhook.py forwards the URL straight to
aiohttp.ClientSession.post with no SSRF gate. The URL is caller-controlled
on two surfaces:
- User notification settings under ENABLE_USER_WEBHOOKS=true — any
authenticated user can set the URL their notifications POST to.
- Automation notification triggers (calendar alerts, etc.).
Without a gate, the URL can target cloud metadata (169.254.169.254 /
fd00:ec2::254), localhost-bound services, RFC1918 internal hosts, or any
other private address reachable from the server process. Blind SSRF — no
response body returned to the caller — but enough to enumerate internal
services via response timing / status codes, and on cloud deployments
enough to issue requests against IMDSv1 if available.
Call validate_url() at the top of post_webhook. The function blocks
private/reserved IPs when ENABLE_RAG_LOCAL_WEB_FETCH is False (the
default), is the project's chosen SSRF gate, and is already applied to
the equivalent fetch surfaces (retrieval, image-load, OAuth profile
picture). Operators who legitimately need to webhook to private IPs
(internal monitoring, self-hosted Slack alternatives, etc.) can set
ENABLE_RAG_LOCAL_WEB_FETCH=True — same opt-out as the other gated
surfaces.
Scope intentionally limited to webhooks. The OAuth discovery and
external reranker paths cwanglab also flagged are admin-configured with
intentional private-IP defaults (reranker defaults to
http://localhost:8080/v1/rerank) and are out of scope per Rule 9 — the
admin owns the URL choice and the operator opt-out exists for them too.
Reported by cwanglab in GHSA-5x9f-85cg-w3hf (cluster canonical with six
closed siblings: g36v-23gj-j69x, 6j8f-h58v-xgmw, xpwv-52pm-p8hj,
v9gp-hv2c-9qv8, fw7w-jrw7-p3v9, x7xq-74rg-m8mf).
Co-authored-by: cwanglab <cwanglab@users.noreply.github.com>
* fix: also pass allow_redirects=False on webhook post_webhook session.post
Companion to the previous commit. validate_url() only validates the
initial URL; aiohttp's default allow_redirects=True would still follow
a 302 to a private-IP target. Same redirect-bypass class as the rh5x
cluster's five call sites, sixth call site to receive the same gate.
Co-authored-by: cwanglab <cwanglab@users.noreply.github.com>
---------
Co-authored-by: cwanglab <cwanglab@users.noreply.github.com>
2026-06-01 23:15:51 +02:00
|
|
|
async with session.post(
|
|
|
|
|
url,
|
|
|
|
|
json=payload,
|
|
|
|
|
ssl=AIOHTTP_CLIENT_SESSION_SSL,
|
|
|
|
|
allow_redirects=AIOHTTP_CLIENT_ALLOW_REDIRECTS,
|
|
|
|
|
) as r:
|
2025-08-15 00:07:02 +04:00
|
|
|
r_text = await r.text()
|
|
|
|
|
r.raise_for_status()
|
2026-03-17 17:58:01 -05:00
|
|
|
log.debug(f'r.text: {r_text}')
|
2025-08-15 00:07:02 +04:00
|
|
|
|
2024-03-20 18:35:02 -07:00
|
|
|
return True
|
|
|
|
|
except Exception as e:
|
2024-03-31 13:17:29 -06:00
|
|
|
log.exception(e)
|
2024-03-31 01:13:39 -07:00
|
|
|
return False
|