Executive brief
NestJS is a popular TypeScript framework used to build server-side web applications. A file upload validation flaw in its common library allows authenticated attackers to bypass security checks by manipulating the Content-Type header, potentially leading to execution of arbitrary code on the server. This could allow an attacker to compromise the application and gain control over backend systems.
Technical details
The vulnerability is a file upload validation bypass (CWE-94: Improper Control of Generation of Code) in the FileTypeValidator component of @nestjs/common. The flaw exists in the file-type.validator.ts file where Content-Type header validation can be circumvented by an authenticated attacker manipulating the Content-Type header during file uploads. Attack requires network access and valid authentication credentials, with user interaction involved. An attacker can bypass file type restrictions to upload and execute arbitrary code on the server. The issue was fixed in versions 10.4.16 and 11.0.16 (patches released March 2025).
Affected products
- NestJS common prior to 10.4.16 and 11.0.0 prior to 11.0.16
Timeline
- 2025-03-14: disclosed: Published as CVE-2024-29409 and GHSA-cj7v-w2c7-cp7c
- 2025-03-14: patched: Fixes released: @nestjs/common 10.4.16 and 11.0.16