Intel

AIKIDO-2026-470568

solspace/craft-freeform is vulnerable to Unrestricted Upload of File with Dangerous Type

Unrestricted Upload of File with Dangerous TypeGHSA-rg3p-gv46-823m Published 2 days ago

53

Medium Risk

This Affects:

PHPsolspace/craft-freeform
5.0.0 - 5.16.0
Fixed in 5.16.1
Are you affected? Scan for Free

TL;DR

Freeform's File Upload Drag & Drop field lets an unauthenticated visitor with access to a public form bypass the field's configured file type and file size restrictions. The traditional upload endpoint skips page validation when the request includes a form_previous_page_button parameter, so the field records no errors even though its checks never ran, and the shared upload service stores the file without enforcing those restrictions itself. The headless drag and drop upload endpoint reaches the same unguarded upload service. The fix makes the upload service enforce the field's file type and file size restrictions before storing the file.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use the File Upload Drag & Drop field on a form accessible to unauthenticated users.

Background info

solspace/craft-freeform is vulnerable to Unrestricted Upload of File with Dangerous Type in versions 5.0.0 - 5.16.0.

How to fix this

Upgrade the solspace/craft-freeform library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform