From 2c3437940ba62f648bd724d54352f87629e86054 Mon Sep 17 00:00:00 2001 From: Acts1631 Date: Thu, 23 Jul 2026 14:57:53 -0400 Subject: [PATCH] Fix upload filename traversal Reject multipart filenames containing path separators before joining them to the selected upload path. This keeps LAN upload clients from creating files outside the selected directory. --- Core/WebServer.cpp | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/Core/WebServer.cpp b/Core/WebServer.cpp index 9c0c469495..2668f858ee 100644 --- a/Core/WebServer.cpp +++ b/Core/WebServer.cpp @@ -548,6 +548,11 @@ enum class MultiPartResult { Done, }; +static bool IsSafeUploadFilename(std::string_view filename) { + return !filename.empty() && filename != "." && filename != ".." && + filename.find_first_of("/\\") == std::string_view::npos; +} + static MultiPartResult HandleMultipartPart(const http::ServerRequest &request, std::string boundary, const Path &uploadPath, ProgressTracker &progress) { std::string firstBoundary = request.In()->ReadLine(); if (firstBoundary != "--" + boundary) { @@ -588,8 +593,8 @@ static MultiPartResult HandleMultipartPart(const http::ServerRequest &request, s } } - if (filename.empty()) { - ERROR_LOG(Log::HTTP, "Didn't receive a filename"); + if (!IsSafeUploadFilename(filename)) { + ERROR_LOG(Log::HTTP, "Invalid upload filename"); return MultiPartResult::RequestError; }