Skip to content
GitLab
Menu
Projects
Groups
Snippets
Loading...
Help
Help
Support
Community forum
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in / Register
Toggle navigation
Menu
Open sidebar
chenpangpang
open-webui
Commits
6c963614
Unverified
Commit
6c963614
authored
Apr 01, 2024
by
KoreLogic Disclosures
Browse files
Suggested mitigation for KL-CAN-2024-002.
parent
edeff20e
Changes
1
Hide whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
18 additions
and
1 deletion
+18
-1
backend/apps/rag/main.py
backend/apps/rag/main.py
+18
-1
No files found.
backend/apps/rag/main.py
View file @
6c963614
...
@@ -448,8 +448,25 @@ def store_doc(
...
@@ -448,8 +448,25 @@ def store_doc(
log
.
info
(
f
"file.content_type:
{
file
.
content_type
}
"
)
log
.
info
(
f
"file.content_type:
{
file
.
content_type
}
"
)
try
:
try
:
is_valid_filename
=
True
unsanitized_filename
=
file
.
filename
if
not
unsanitized_filename
.
isascii
():
is_valid_filename
=
False
unvalidated_file_path
=
f
"
{
UPLOAD_DIR
}
/
{
unsanitized_filename
}
"
dereferenced_file_path
=
str
(
Path
(
unvalidated_file_path
).
resolve
(
strict
=
False
))
if
not
dereferenced_file_path
.
startswith
(
UPLOAD_DIR
):
is_valid_filename
=
False
if
is_valid_filename
:
file_path
=
dereferenced_file_path
else
:
raise
HTTPException
(
status_code
=
status
.
HTTP_400_BAD_REQUEST
,
detail
=
ERROR_MESSAGES
.
DEFAULT
(),
)
filename
=
file
.
filename
filename
=
file
.
filename
file_path
=
f
"
{
UPLOAD_DIR
}
/
{
filename
}
"
contents
=
file
.
file
.
read
()
contents
=
file
.
file
.
read
()
with
open
(
file_path
,
"wb"
)
as
f
:
with
open
(
file_path
,
"wb"
)
as
f
:
f
.
write
(
contents
)
f
.
write
(
contents
)
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
.
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment