Security vulnerabilities

  • Status Closed
  • Assigned To
    cbay
  • Private
Attached to Project: Security vulnerabilities
Opened by malko - 09.10.2026
Last edited by cbay - 09.10.2026

FS#523 - Stored Cross-Site Scripting (XSS) via File Upload / PDF Rendering

Affected endpoint: `https://security.alwaysdata.com/?getfile=290`

Vulnerability type: Cross-Site Scripting (XSS)
Status: Requires confirmation of application-origin execution
Severity: To be determined based on the execution context and affected users

## Summary

A potentially unsafe file-upload and file-rendering behavior was identified on the application. A test PDF, `test-xss.pdf`, was uploaded and accessed through the application's file retrieval endpoint.

When the PDF was opened, a browser notification displaying “XSS Tested Successfully” appeared, indicating that script-related behavior was triggered in the document-viewing workflow.

Further validation is required to determine whether the behavior constitutes stored XSS in the application's security origin or JavaScript execution isolated to the PDF viewer.

## Steps to Reproduce

1. Upload a PDF containing a benign JavaScript execution test through the application's file-upload functionality.
2. Open the uploaded file using the application's file retrieval endpoint.
3. Observe the PDF viewer and check whether the test notification appears.
4. If authorized, verify the execution origin and whether the same behavior affects another user who opens the uploaded file.

## Observed Result

A browser notification displaying “XSS Tested Successfully” appeared while the PDF was open in the browser.

## Expected Result

Uploaded files should be served and rendered safely. Untrusted document content must not execute script with privileges belonging to the application's origin.

## Security Impact

If the uploaded document can execute JavaScript in the application's origin when opened by another user, an attacker might be able to perform actions within that user's authenticated session, subject to the application's security controls.

If execution is confined to a sandboxed PDF viewer or a separate origin, the impact may be substantially lower.

## Recommendations

* Serve untrusted uploads from a separate, appropriately isolated origin.
* Apply strict file-type validation and safe content-disposition headers.
* Configure an appropriate Content Security Policy where applicable.
* Ensure PDF rendering and JavaScript execution follow the viewer's security model.
* Test uploaded files with a current, securely configured PDF viewer.
* Verify that other users cannot be affected through the same upload-and-view workflow.

## Evidence

The supplied screenshot shows the notification “XSS Tested Successfully” while viewing `test-xss.pdf` through the application's file endpoint.

Closed by  cbay
09.10.2026 13:12
Reason for closing:  Invalid
Admin
cbay commented on 09.10.2026 13:12

Hello,

We're running the latest Flyspray version (1.0-rc11) so you should report it to them.

Kind regards,
Cyril

Loading...

Available keyboard shortcuts

Tasklist

Task Details

Task Editing