Illustrative only - not an engagement finding
Unsafe Uploaded Files Can Run in a Staff Member's Browser
Critical
See where this finding applies on the diagrams: browser-to-API-to-storage path · CP1 public ingress
Illustrative only - not an engagement finding
Unsafe Uploaded Files Can Run in a Staff Member's Browser
- Business summary
- When a staff member previews an uploaded file, the browser may treat code inside that file as part of the staff application. That code could read information shown to the reviewer, call the API through the reviewer's signed-in session or steal a browser access token. An uploaded document must never receive the same browser access as the application.
- Assessment profile
- Expected fix Verification
-
-
Expected fix Check what the file really contains FastAPI upload checks and background worker: Inspect the file's bytes and structure instead of trusting its name or the type reported by the uploader.Verification Reject files disguised by name or type A file containing active content is rejected or forced to download even when it uses an allowed filename or reported type.
-
Expected fix Preview only formats that cannot run code FastAPI preview rules: Display only specifically approved non-executable formats. Force every unknown or active format to download instead.Verification Keep safe previews working Approved documents display correctly, while unknown or executable formats cannot run in the browser.
-
Expected fix Open previews in an isolated browser area React preview and Blob Storage delivery: Use a separate web address or a restricted frame that cannot run scripts as part of the staff application.Verification Keep the file separate from the application Code in the preview cannot read the staff page, call its authenticated APIs or communicate through unrestricted scripts.
-
Expected fix Tell the browser exactly how to handle the file FastAPI or Blob Storage response: Send the approved file type, display-or-download instruction,
nosniffsetting and content security policy.Verification Confirm every browser restriction The file response contains the required type, display-or-download instruction,nosniffsetting and content security policy. -
Expected fix Keep sign-in tokens away from page scripts React and Microsoft authentication-library session handling: Store Entra ID tokens where code inside a preview or injected into the page cannot read them.Verification Confirm the preview cannot steal a token Hostile test content cannot read token storage or obtain the staff member's access token.
-