Fix upload path-traversal RCE vector, patch all known-vulnerable deps

Path traversal (CWE-22/CWE-73): event-image, branding (logo/favicon),
and event-attachment uploads built the saved filename from the
client-supplied original filename with no sanitization, and multer's
diskStorage joins that straight into the destination path. A crafted
filename containing `../` sequences could write the uploaded file
anywhere the server process has write access — reachable by any
supervisor-level account, and briefly pre-auth via the branding
uploads during initial /setup. Filenames are now always server-
generated (random bytes + validated extension); the original name is
kept only as display metadata.

Dependencies: express-rate-limit was declared only at the repo root
despite being required directly by backend/src/index.js, so a plain
`cd backend && npm install` (per the deployment doc) would never
install it — moved it into backend/package.json. Bumped next off a
version affected by a critical unauthenticated RCE (React Flight
protocol) and switched it from an exact pin to a caret range so future
patches install automatically. Bumped multer/nodemailer/jsonwebtoken/
uuid to patched versions, with an override forcing the vulnerable
nested uuid inside exceljs and the vulnerable postcss bundled inside
next to the patched versions too. `npm audit` is now clean (0
vulnerabilities) across root, backend, and frontend.

Hardening: jwt.verify() now pins algorithms: ['HS256'] instead of
trusting the token header; /uploads now serves with a restrictive CSP
and X-Content-Type-Options: nosniff so an uploaded SVG containing
<script> can't execute if opened directly.

Verified: backend's Jest suite passes, the backend boots and serves
real requests on the bumped deps, and `next build` compiles/type-
checks cleanly on the bumped frontend deps.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CSWFWQsjTc9GyffPiXEDQT
This commit is contained in:
2026-08-28 11:33:05 +02:00
co-authored by Claude Sonnet 5
parent 5a416916c9
commit 032d3c032e
11 changed files with 2197 additions and 3160 deletions
+5 -1
View File
@@ -3,6 +3,7 @@ const { v4: uuidv4 } = require('uuid');
const multer = require('multer');
const path = require('path');
const fs = require('fs');
const crypto = require('crypto');
const { assertEventOpen } = require('../utils/cashupUtils');
const { logAdminAction } = require('../utils/adminAudit');
const { getClientIp } = require('../utils/requestUtils');
@@ -987,7 +988,10 @@ const attachmentsStorage = multer.diskStorage({
}
},
filename: function (req, file, cb) {
const unique = `${Date.now()}-${file.originalname}`;
// Extension only — file.originalname is untrusted and joining it into a
// path allows `../` traversal to write outside the upload directory.
const ext = path.extname(file.originalname).toLowerCase();
const unique = `event-file-${Date.now()}-${crypto.randomBytes(8).toString('hex')}${ext}`;
cb(null, unique);
}
});
+11 -4
View File
@@ -1,7 +1,15 @@
const path = require('path');
const fs = require('fs');
const crypto = require('crypto');
const multer = require('multer');
// Builds a filename multer can never be tricked into escaping the upload
// directory with — extension only, no attacker-controlled path segments.
// (file.originalname is untrusted; joining it into a path allows `../` traversal.)
function safeFilename(prefix, ext) {
return `${prefix}-${Date.now()}-${crypto.randomBytes(8).toString('hex')}${ext}`;
}
// Setup multer storage
const storage = multer.diskStorage({
destination: function (req, file, cb) {
@@ -24,8 +32,7 @@ const storage = multer.diskStorage({
}
},
filename: function (req, file, cb) {
const uniqueName = `${Date.now()}-${file.originalname}`;
cb(null, uniqueName);
cb(null, safeFilename('event', path.extname(file.originalname).toLowerCase()));
}
});
@@ -54,7 +61,7 @@ const logoStorage = multer.diskStorage({
}
},
filename: function (req, file, cb) {
cb(null, `logo-${Date.now()}${path.extname(file.originalname).toLowerCase()}`);
cb(null, safeFilename('logo', path.extname(file.originalname).toLowerCase()));
}
});
@@ -82,7 +89,7 @@ const faviconStorage = multer.diskStorage({
}
},
filename: function (req, file, cb) {
cb(null, `favicon-${Date.now()}${path.extname(file.originalname).toLowerCase()}`);
cb(null, safeFilename('favicon', path.extname(file.originalname).toLowerCase()));
}
});