strix/skills/vulnerabilities/insecure_file_uploads.md
Upload surfaces are high risk: server-side execution (RCE), stored XSS, malware distribution, storage takeover, and DoS. Modern stacks mix direct-to-cloud uploads, background processors, and CDNs—authorization and validation must hold across every step.
<?php echo 1; ?>; place where PHP is executed../../ to escape extraction dir; symlink-in-zip pointing outside target; nested zipsSecure uploads are a pipeline property. Enforce strict type, size, and header controls; transform or strip active content; never execute or inline-render untrusted uploads; and keep storage private with controlled, signed access.