← Inspection rules
SEC-015 / v1.0.0 / 2026-10-09
Restrict execution of uploaded files
Editorial inspection guidance. Start with read-only permissions; fixes, credential revocation, and production changes follow the owner’s authorization.
Applicability
Services that upload, ingest, store, or serve files.
Where to look first
- Upload storage, serving configuration, executable handlers, and processing-account privileges.
Inspection steps
- Compare configuration and architecture to check whether upload storage overlaps application or code deployment paths.
- Identify paths that could execute stored files and privileges reaching other environments.
- Review tests from an owner-authorized environment. Without evidence, mark unverified; do not submit attack files to production.
Remediation direction
- Separate storage and serving from code execution; remove executable handlers and unnecessary privileges.
Evidence required for completion
- Record configuration and test evidence of denied execution and successful normal storage and serving.
Limits and unverified scope
- Filename restrictions alone do not prove non-execution. Review image-processing and conversion-library vulnerabilities separately.
- This link is inspection guidance; it does not establish uploads as the intrusion cause.