Skip to content

Topic

File upload security

Practices and flaws around accepting user-supplied files, including type validation, content sanitization, storage, and the headers used to serve uploaded content.

Current clusters

build1 publisher

An <object> tag turns an uploaded SVG into stored XSS for every visitor

OopsSec Store, a deliberately vulnerable Next.js app, lets an admin-uploaded SVG run JavaScript in every visitor's browser. It works because the server trusts the client-set Content-Type and the product page renders SVGs through an <object> tag.

Publishers:dev.to

Reality

Evidence62
Adoption
Insufficient
Hype gap+8
Incentives40
Confidence72