← Inspection rules

SEC-015 / v1.0.0 / 2026-10-09

Restrict execution of uploaded files

Editorial inspection guidance. Start with read-only permissions; fixes, credential revocation, and production changes follow the owner’s authorization.

Applicability

Services that upload, ingest, store, or serve files.

Where to look first

  • Upload storage, serving configuration, executable handlers, and processing-account privileges.

Inspection steps

  1. Compare configuration and architecture to check whether upload storage overlaps application or code deployment paths.
  2. Identify paths that could execute stored files and privileges reaching other environments.
  3. Review tests from an owner-authorized environment. Without evidence, mark unverified; do not submit attack files to production.

Remediation direction

  • Separate storage and serving from code execution; remove executable handlers and unnecessary privileges.

Evidence required for completion

  • Record configuration and test evidence of denied execution and successful normal storage and serving.

Limits and unverified scope

  • Filename restrictions alone do not prove non-execution. Review image-processing and conversion-library vulnerabilities separately.
  • This link is inspection guidance; it does not establish uploads as the intrusion cause.