file-upload
Safeguard articles tagged "file-upload" — guides, analysis, and best practices for software supply chain and application security.
10 articles
An Uploaded File Can Be Two Formats at Once, and Your Validation Only Checked One
A user's file passes every image validation check your upload handler runs. It is also, independently and simultaneously, a valid HTML document, and browser MIME sniffing can choose to render that instead when your response headers do not stop it.
Inbound Email Is an Unauthenticated API You Forgot You Built
Reply to a notification and it appears in the ticket. Forward a document and it imports. The From header is a string the sender chooses, and it is what most implementations key on.
A Presigned URL Is a Capability You Minted Without Thinking About It
Anyone holding the string can do what it permits, with no identity check, until it expires. Every mistake is a variation of one thing: handing out more capability than intended, for longer than intended.
Four CMS Plugins, Four Vendors, the Same Unrestricted Upload Bug in Three Days
Four Joomla extensions from unrelated developers had unauthenticated file upload vulnerabilities confirmed exploited within a three-day window in July 2026, every one scoring CVSS 9.8.
Preventing path traversal in Node.js file upload and serving code
path.join() doesn't stop ../../etc/passwd — CVE-2024-12905 and Zip Slip show why Node.js needs explicit containment checks, not just path normalization.
browser-image-compression: Is Client-Side Image Compression Safe?
browser-image-compression shrinks images in the browser before upload. Here is how it works, its security trade-offs, and why client-side compression is never validation.
CVE-2023-42794: The Apache Tomcat Incomplete Cleanup DoS Explained
An unreleased refactoring in Tomcat's bundled Commons FileUpload left temp files undeleted on Windows, risking a disk-exhaustion DoS. Here is what CVE-2023-42794 is and how to fix it.
Multer on npm: Security Review and the 2025 DoS Fixes
Multer had a run of denial-of-service advisories through 2025. Here is what each one was, which version fixes them, and how to use the npm package safely.
Formidable npm: Security Review and Safe Usage of the File-Upload Parser
A security review of the formidable npm package: the file-upload risks, the CVEs assigned against it, and how to configure it so uploads stay safe.
Is the Busboy npm Package Safe? A Security Review
The busboy npm package parses multipart form data in Node.js. Here is its current security status, the dicer history that once bit it, and how to use it safely.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.