When using wildcard validation to validate a given file or image field array (files.*), a user-crafted malicious request could potentially bypass the validation rules.
{
"nvd_published_at": "2025-03-05T19:15:39Z",
"github_reviewed": true,
"github_reviewed_at": "2025-03-05T19:09:39Z",
"severity": "MODERATE",
"cwe_ids": [
"CWE-155"
]
}