Executive brief
Mantis Bug Tracker (MantisBT) is an open-source platform used by organizations to track software bugs and project issues. A security flaw in the file attachment system allows attackers to bypass the application's security policies by uploading specially crafted files that the system incorrectly identifies as executable scripts. If an attacker also finds a way to inject basic HTML into the site, they can use this flaw to execute malicious code in a victim's browser, potentially leading to the theft of sensitive session data or unauthorized actions.
Technical details
A Content Security Policy (CSP) bypass exists in MantisBT versions 2.28.1 and below within the file_download.php component. The vulnerability occurs because the application uses PHP's finfo_buffer (via file_create_finfo) to determine MIME types; certain file headers (e.g., #!/usr/bin/env node) cause the system to serve attachments with an 'application/javascript' MIME type. An attacker with low privileges can upload such a file and, if a separate HTML/XSS injection point exists, reference the attachment in a <script> tag to bypass 'script-src' directives. This bypasses the 'nosniff' protection because the served MIME type is valid for JavaScript. The issue is resolved in version 2.28.2 by forcing 'application/javascript' files to be downloaded as attachments rather than served inline.
Affected products
- MantisBT MantisBT <= 2.28.1
Timeline
- 2026-04-12: disclosed: Initial report by siunam
- 2026-05-09: advisory: GitHub Security Advisory published
- 2026-05-22: patched: Version 2.28.2 released