GHSA-9qpg-3cf8-w33x: Malicious File Upload
Impact Under certain local upload configurations, an uploaded XML file and stylesheet could execute JavaScript in the Payload origin when a logged-in user opens the file.
You are affected if: - You accept XML uploads (accepted by default).
Patches Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Workarounds Disallow XML/XSL uploads.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/payloadto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34 - Upgrade
Upgrade
npm/payloadto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
Payload packagesto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
Payload packagesto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34 - Configuration
Disallow XML and XSL uploads.
Payload XML/XSL uploads = disallow