VDB
Sign up
LOW3.7

GHSA-qvfw-j98x-7q72

multer vulnerable to file size limit bypass via async fileFilter race condition

Quick fix

GHSA-qvfw-j98x-7q72 — multer: upgrade to the fixed version with the command below.

npm install multer@2.3.0

Details

### Impact

When `multer` is configured with an asynchronous `fileFilter`, the `limits.fileSize` limit can be bypassed. The `'limit'` event is registered inside the async `fileFilter` callback, so if a file exceeds `limits.fileSize` before that callback runs, the event is missed and the oversized upload is accepted instead of being rejected with a `LIMIT_FILE_SIZE` error. Applications that rely on `limits.fileSize` to reject oversized uploads are affected on all upload methods (`.single()`, `.array()`, `.fields()`, `.any()`). Uploads using a synchronous `fileFilter` are not affected.

### Patches

Users should upgrade to `2.3.0`.

### Workarounds

Use a synchronous `fileFilter`, or validate the uploaded file size after the upload completes.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/multer
Introduced in: 0Fixed in: 2.3.0
Fixnpm install multer@2.3.0

References