When using wildcard validation to validate a given file or image field array (files.*
), a user-crafted malicious request could potentially bypass the validation rules.
{ "nvd_published_at": "2025-03-05T19:15:39Z", "cwe_ids": [ "CWE-155" ], "github_reviewed_at": "2025-03-05T19:09:39Z", "github_reviewed": true, "severity": "MODERATE" }