Fix upload filename traversal

Reject multipart filenames containing path separators before joining
them to the selected upload path. This keeps LAN upload clients
from creating files outside the selected directory.
This commit is contained in:
Acts1631 committed 2026-07-23 15:04:04 -04:00
1 parent c119d9b258
commit 2c3437940b
1 file changed
+7 -2
+7 -2
View File
@@ -548,6 +548,11 @@ enum class MultiPartResult {
Done,
};
static bool IsSafeUploadFilename(std::string_view filename) {
return !filename.empty() && filename != "." && filename != ".." &&
filename.find_first_of("/\\") == std::string_view::npos;
}
static MultiPartResult HandleMultipartPart(const http::ServerRequest &request, std::string boundary, const Path &uploadPath, ProgressTracker &progress) {
std::string firstBoundary = request.In()->ReadLine();
if (firstBoundary != "--" + boundary) {
@@ -588,8 +593,8 @@ static MultiPartResult HandleMultipartPart(const http::ServerRequest &request, s
}
}
if (filename.empty()) {
ERROR_LOG(Log::HTTP, "Didn't receive a filename");
if (!IsSafeUploadFilename(filename)) {
ERROR_LOG(Log::HTTP, "Invalid upload filename");
return MultiPartResult::RequestError;
}