Executive brief
Nhost Storage, a service used for managing file uploads and storage, is vulnerable to a flaw where it incorrectly trusts the file type claimed by a user's browser or application. This allows an attacker to upload files that appear to be one type (like a harmless image) but actually contain different content, potentially bypassing security filters. This could lead to files being handled incorrectly by web browsers or content delivery networks, which might result in security risks for users who later access those files.
Technical details
The Nhost storage service's file upload handler in `services/storage/controller/upload_files.go` contains a logic flaw in the `getMultipartFile` function. The service prioritizes the client-provided `Content-Type` header; if it is present and not set to `application/octet-stream`, the server skips its internal MIME type detection via `mimetype.DetectReader`. This allows a remote attacker to upload files with arbitrary MIME types in the metadata, bypassing any MIME-type-based restrictions configured on storage buckets. This can lead to incorrect file handling by downstream consumers like browsers or CDNs. The issue is fixed in version 0.0.0-20260318074820-c4bd53f042d7.
Affected products
- Nhost Nhost Storage < 0.0.0-20260318074820-c4bd53f042d7
Timeline
- 2026-03-18: advisory: GitHub Advisory published
- 2026-03-18: patched: Fix committed to repository
- 2026-03-20: disclosed: NVD publication date