GHSA-2rm3-333w-xvc4
### Impact All users of DotVVM with configured file upload storage are affected. DotVVM allows anyone to upload files to the application, potentially causing denial of service by filling the disk. ### Patches Since version 4.3.15, 4.2.11 and 5.0.0-preview09, DotVVM requires all file upload request to have a cryptographic token, which is automatically generated by the FileUpload component. This means that users without access to any page with the FileUpload component cannot upload any files. The patch also add the `DotvvmConfiguration.Security.AuthorizeFileUpload` option which allow you to further restrict which users can upload files. ### Workarounds As a workaround, you can temporarily disable file upload by removing `AddUploadedFileStorage` or `AddDefaultTempStorage` from your DotVVM configuration. Even with the patch, we recommend configuring file upload to use a dedicated partition with limited size. ### References * DotVVM file upload configuration: https://www.dotvvm.com/docs/4.0/pages/concepts/upload-and-download-files/upload-files
Properties
- ghsa_id
- GHSA-2rm3-333w-xvc4
- summary
- DotVVM: Unrestricted file upload
- severity
- medium
- cvss_score
- 5.3
- cve_id
- GHSA-2rm3-333w-xvc4
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- is_ghsa_only
- true
- ghsa_published
- 2026-06-19T15:09:18Z
- source_url
- https://github.com/advisories/GHSA-2rm3-333w-xvc4
- ghsa_updated
- 2026-06-19T15:09:18Z
Related Entities (4)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph