Skip to content

Secure file upload architecture: preventing webshell execution, SVG XSS, and path traversal

How to build secure file upload handling: defeating webshell execution, neutralizing malicious SVG XSS vectors, and preventing path traversal attacks.

By BugSnaps Security Research · · 8 min read

Allowing users to upload files is a core requirement for profile avatars, resume submissions, and document attachments. However, improper file upload handling is one of the most direct paths to server compromise via executable webshells or stored client-side XSS.

Common file upload attack vectors

Attackers exploit several common implementation oversights in upload endpoints:

  • Direct webshell execution: uploading `.php`, `.jsp`, or `.aspx` scripts to a web-accessible directory where the web server executes them upon direct HTTP request.
  • Path traversal filenames: uploading files named `../../../../etc/cron.d/malicious` to overwrite sensitive server configuration files.
  • SVG Cross-Site Scripting: uploading `.svg` image files containing `<script>` tags, which execute when viewed directly in modern browsers.
  • MIME-type spoofing: relying solely on client-supplied `Content-Type` headers or file extensions without verifying actual magic bytes.

Secure upload architecture patterns

Never store uploaded files on the local web server filesystem. Stream uploads directly to an isolated cloud object storage service (such as AWS S3 or Cloudflare R2) using pre-signed upload URLs. Generate random cryptographic filenames, strip metadata, enforce file size limits, and serve files from a dedicated, cookieless domain with `Content-Disposition: attachment`.

Store uploads in dedicated cloud storage buckets with public execution disabled, and serve files strictly with forced download headers or strict content isolation.

Run a real pentest on your app - free.

Sign in, prove you own the domain, and MyPentest maps and tests it. No credit card.