Executive brief
LiquidFiles, a file transfer appliance used by government and healthcare sectors, contains a security flaw in how it handles file previews. An authenticated attacker can upload a specially crafted file that, when viewed by another user (such as an administrator), executes malicious code in their web browser. This could allow an attacker to take over the account of the person viewing the file, potentially leading to full system compromise and the theft of sensitive data.
Technical details
An HTML injection vulnerability exists in the file view endpoint of LiquidFiles v4.2.7. The vulnerability arises because the application fails to properly sanitize filenames in activity logs and omits Content Security Policy (CSP) headers on certain routes served by the reverse proxy. An authenticated attacker can exploit this by uploading a malicious HTML file and using a secondary XSS gadget (such as a meta-refresh payload in a filename) to redirect a victim to the file preview. Because the preview endpoint lacks CSP protections, the injected JavaScript executes in the victim's browser context. This can lead to session hijacking or full administrative compromise if an admin views the logs. The issue is addressed in version 4.2.8.
Affected products
- LiquidFiles LiquidFiles 4.2.7
Timeline
- 2026-07-01: disclosed: Vulnerability details published by Securing.pl
- 2026-07-07: advisory: CVE published to NVD
- 2026-07-07: patched: Fix available in version 4.2.8