Allowing users to upload files is a core requirement for profile avatars, resume submissions, and document attachments. However, improper file upload handling is one of the most direct paths to server compromise via executable webshells or stored client-side XSS.
Common file upload attack vectors
Attackers exploit several common implementation oversights in upload endpoints:
- Direct webshell execution: uploading `.php`, `.jsp`, or `.aspx` scripts to a web-accessible directory where the web server executes them upon direct HTTP request.
- Path traversal filenames: uploading files named `../../../../etc/cron.d/malicious` to overwrite sensitive server configuration files.
- SVG Cross-Site Scripting: uploading `.svg` image files containing `<script>` tags, which execute when viewed directly in modern browsers.
- MIME-type spoofing: relying solely on client-supplied `Content-Type` headers or file extensions without verifying actual magic bytes.
Secure upload architecture patterns
Never store uploaded files on the local web server filesystem. Stream uploads directly to an isolated cloud object storage service (such as AWS S3 or Cloudflare R2) using pre-signed upload URLs. Generate random cryptographic filenames, strip metadata, enforce file size limits, and serve files from a dedicated, cookieless domain with `Content-Disposition: attachment`.
Store uploads in dedicated cloud storage buckets with public execution disabled, and serve files strictly with forced download headers or strict content isolation.