logo

Database

Insecure file upload In payload

Description

Payload: Bypassed sanitization of user uploaded SVGs

Impact

A malicious SVG file upload could bypass sanitization, be stored, and execute attacker-controlled JavaScript (XSS) after a user downloads it and opens it.

You are affected if:

    You have a collection configured to upload and allow SVG files which can then be downloaded by users.

Patches

The fix validates SVG content on every upload path and hardens SVG/XML delivery so stored SVGs cannot frame attacker content.

Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Workarounds

Disallow SVG uploads, or serve uploaded SVGs as downloads with Content-Disposition: attachment and a strict CSP. These mitigations reduce exposure but do not replace upgrading when the patched release is available.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions
FLAT-BMWK5 – Vulnerability | Fluid Attacks Database