Executive brief
Mothra, a web browser for the Plan 9-based 9front operating system, contains a flaw that allows websites to automatically select files from a user's computer for upload. An attacker could create a malicious website that silently picks sensitive local files and hides the upload form from view. If a user interacts with the page, their private files could be sent to the attacker's server without their knowledge or consent.
Technical details
A vulnerability in Mothra's HTML form parsing logic (forms.c) fails to clear default values when an input type is set to 'file'. This allows a remote web server to pre-populate a file upload field with a specific local file path. While Mothra does not support CSS-based hiding, attackers can use techniques like excessive padding with empty headings to push the pre-filled form element out of the visible viewport. When a user submits the form (e.g., via a 'Submit' button they believe does something else), the browser transmits the contents of the specified local file to the attacker's server. The fix involves explicitly clearing the input value when the 'file' type is recognized during form initialization.
Affected products
- 9front Mothra Prior to commit d145acc9ef0da47131af6ad94e87264e04870d47
Timeline
- 2026-05-11: patched: Fix committed to 9front repository
- 2026-05-22: disclosed: CVE published and advisory released