Via a manipulated API request it's possible to upload a file that doesn't adhere with the configured allowable file extensions.
Patched in 15.4.2 and 16.0.0.
None available.
{ "nvd_published_at": "2025-06-03T19:15:39Z", "github_reviewed_at": "2025-06-04T23:50:55Z", "cwe_ids": [ "CWE-434" ], "severity": "MODERATE", "github_reviewed": true }