mediumCVSS 5.3Vulnerability

GHSA-2rm3-333w-xvc4

### Impact All users of DotVVM with configured file upload storage are affected. DotVVM allows anyone to upload files to the application, potentially causing denial of service by filling the disk. ### Patches Since version 4.3.15, 4.2.11 and 5.0.0-preview09, DotVVM requires all file upload request to have a cryptographic token, which is automatically generated by the FileUpload component. This means that users without access to any page with the FileUpload component cannot upload any files. The patch also add the `DotvvmConfiguration.Security.AuthorizeFileUpload` option which allow you to further restrict which users can upload files. ### Workarounds As a workaround, you can temporarily disable file upload by removing `AddUploadedFileStorage` or `AddDefaultTempStorage` from your DotVVM configuration. Even with the patch, we recommend configuring file upload to use a dedicated partition with limited size. ### References * DotVVM file upload configuration: https://www.dotvvm.com/docs/4.0/pages/concepts/upload-and-download-files/upload-files

Properties

ghsa_id
GHSA-2rm3-333w-xvc4
summary
DotVVM: Unrestricted file upload
severity
medium
cvss_score
5.3
cve_id
GHSA-2rm3-333w-xvc4
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
is_ghsa_only
true
ghsa_published
2026-06-19T15:09:18Z
source_url
https://github.com/advisories/GHSA-2rm3-333w-xvc4
ghsa_updated
2026-06-19T15:09:18Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]nuget/DotVVM

AFFECTS (1)

[Software]nuget/DotVVM

HAS_WEAKNESS (1)

[Weakness]Unrestricted Upload of File with Dangerous Type

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-2rm3-333w-xvc4 (CVSS 5.3) — Ninja Signal Threat Intelligence | Ninja Signal