{"data":{"id":"magento2-40583","source":"github-pr","sourceRef":"magento/magento2#40583","title":"Validate frontend input type for file uploads","pr":{"number":40583,"url":"https://github.com/magento/magento2/pull/40583","author":"SkyMulley","mergedAt":"2026-06-08T10:42:28Z","mergeCommit":"f6852a78d51a2db1e366a83c6f456f35e678d53d","headCommit":"bd25da414f7f8eb6fa23c8698b9c33fca4183eba","baseRef":"2.4-develop","diffSha256":"23b6f48557d7fc5cd9a2b9cb369c44e963125668172a070a79f86aa1f55edfc7"},"issues":[{"number":40795,"url":"https://github.com/magento/magento2/issues/40795","title":"[Issue] Validate frontend input type for file uploads","labels":["Area: Account","Component: Customer","Issue: Confirmed","Priority: P3","Progress: PR Created","Progress: done","Reproduced on 2.4.x","Triage: Dev.Experience"],"kind":"pr-derived"}],"fixedIn":null,"containingTags":[],"reportedOn":null,"codeMatch":{"2.4.6":"clean","2.4.6-p1":"clean","2.4.6-p2":"clean","2.4.6-p3":"clean","2.4.6-p4":"clean","2.4.6-p5":"clean","2.4.6-p6":"clean","2.4.6-p7":"clean","2.4.6-p8":"clean","2.4.6-p9":"clean","2.4.6-p10":"clean","2.4.6-p11":"clean","2.4.6-p12":"clean","2.4.6-p13":"clean","2.4.6-p14":"clean","2.4.6-p15":"clean","2.4.7":"clean","2.4.7-p1":"clean","2.4.7-p2":"clean","2.4.7-p3":"clean","2.4.7-p4":"clean","2.4.7-p5":"clean","2.4.7-p6":"clean","2.4.7-p7":"clean","2.4.7-p8":"clean","2.4.7-p9":"clean","2.4.7-p10":"clean","2.4.8":"clean","2.4.8-p1":"clean","2.4.8-p2":"clean","2.4.8-p3":"clean","2.4.8-p4":"clean","2.4.8-p5":"clean","2.4.9":"clean"},"affectedVersions":["2.4.6","2.4.6-p1","2.4.6-p2","2.4.6-p3","2.4.6-p4","2.4.6-p5","2.4.6-p6","2.4.6-p7","2.4.6-p8","2.4.6-p9","2.4.6-p10","2.4.6-p11","2.4.6-p12","2.4.6-p13","2.4.6-p14","2.4.6-p15","2.4.7","2.4.7-p1","2.4.7-p2","2.4.7-p3","2.4.7-p4","2.4.7-p5","2.4.7-p6","2.4.7-p7","2.4.7-p8","2.4.7-p9","2.4.7-p10","2.4.8","2.4.8-p1","2.4.8-p2","2.4.8-p3","2.4.8-p4","2.4.8-p5","2.4.9"],"components":["magento/module-customer"],"files":[{"path":"app/code/Magento/Customer/Model/FileUploader.php","change":"modified","package":"magento/module-customer"}],"stripped":{"tests":["app/code/Magento/Customer/Test/Unit/Model/FileUploaderTest.php"],"docs":[],"outsideCode":[]},"linesChanged":4,"mergeBatched":false,"excluded":null,"sections":{"description":"The customer address file upload endpoint (`Customer/Controller/Address/File/Upload.php`) did not validate whether the requested attribute's `frontend_input` type was `file` or `image` before proceeding with the upload.","stepsToReproduce":"1. Create a custom customer address attribute with `frontend_input` type of `text` (e.g. `my_text_attribute`)\n2. Log in as a customer and send a `POST` request to `/customer/address/file/upload` with `custom_attributes[my_text_attribute]` as the file field, uploading a `.php` file\n3. **Without fix**: file is accepted and saved to `pub/media/customer_address/tmp/`\n4. **With fix**: request returns an error — `Attribute \"my_text_attribute\" does not support file uploads.` — and no file is written to disk\n5. Verify that uploading via a legitimate `file` or `image` type attribute still works as expected","expectedResult":null,"actualResult":null,"source":"pr"},"signatures":["The fix adds a check immediately after fetching the attribute metadata, throwing a `LocalizedException` if the `frontend_input` is not `file` or `image`."],"labels":{"area":["Account"],"component":["Customer"],"priority":"P3","severity":null,"reportedOn":[]},"categories":["Customer"],"triage":{"model":"@cf/cloudflare/clef","requestHash":"700214d6e4c35f320af940b1115414e2767df7356d6491e58bf68a4a2285b201","isBugfix":0.9555,"changeKind":{"choice":"bugfix","probabilities":{"bugfix":0.9217,"feature":0.0256,"refactor":0.0195,"tests_only":0.0177,"docs_only":0.0073,"dependency":0.0082},"confidence":0.8212},"scope":{"score":0.3645,"probabilities":{"0":0.6858,"1":0.264,"2":0.0502},"confidence":0.3138},"risk":{"score":0.2282,"probabilities":{"0":0.8426,"1":0.0867,"2":0.0707},"confidence":0.5837},"area":{"choice":"customer","probabilities":{"catalog":0.0071,"checkout":0.0049,"customer":0.9564,"admin":0.0082,"graphql_api":0.0049,"framework":0.0063,"frontend":0.0081,"other":0.0041},"confidence":0.9028},"securityRelevant":0.905,"reportedVersion":{"choice":"unspecified","probabilities":{"2.4.0":0.0037,"2.4.0-p1":0.0037,"2.4.1":0.0037,"2.4.1-p1":0.0032,"2.4.2":0.0048,"2.4.2-p1":0.0046,"2.4.2-p2":0.0064,"2.4.3":0.0081,"2.4.3-p1":0.0077,"2.4.3-p2":0.0098,"2.4.3-p3":0.006,"2.4.4":0.0108,"2.4.4-p1":0.0074,"2.4.4-p10":0.0058,"2.4.4-p11":0.0064,"2.4.4-p12":0.0055,"2.4.4-p13":0.006,"2.4.4-p14":0.0069,"2.4.4-p15":0.0054,"2.4.4-p16":0.0071,"2.4.4-p17":0.0058,"2.4.4-p18":0.0045,"2.4.4-p2":0.0024,"2.4.4-p3":0.0025,"2.4.4-p4":0.0028,"2.4.4-p5":0.003,"2.4.4-p6":0.0037,"2.4.4-p7":0.0038,"2.4.4-p8":0.0038,"2.4.4-p9":0.0035,"2.4.5":0.0139,"2.4.5-p1":0.0118,"2.4.5-p10":0.0074,"2.4.5-p11":0.0127,"2.4.5-p12":0.0116,"2.4.5-p13":0.0091,"2.4.5-p14":0.0081,"2.4.5-p15":0.0071,"2.4.5-p16":0.0101,"2.4.5-p17":0.009,"2.4.5-p2":0.0031,"2.4.5-p3":0.005,"2.4.5-p4":0.0059,"2.4.5-p5":0.005,"2.4.5-p6":0.0059,"2.4.5-p7":0.0057,"2.4.5-p8":0.0049,"2.4.5-p9":0.0048,"2.4.6":0.0321,"2.4.6-p1":0.0239,"2.4.6-p10":0.0101,"2.4.6-p11":0.0141,"2.4.6-p12":0.0121,"2.4.6-p13":0.0122,"2.4.6-p14":0.0114,"2.4.6-p15":0.0106,"2.4.6-p2":0.0041,"2.4.6-p3":0.0075,"2.4.6-p4":0.0085,"2.4.6-p5":0.0073,"2.4.6-p6":0.0082,"2.4.6-p7":0.0088,"2.4.6-p8":0.006,"2.4.6-p9":0.0056,"2.4.7":0.0189,"2.4.7-p1":0.0186,"2.4.7-p10":0.0086,"2.4.7-p2":0.0069,"2.4.7-p3":0.0141,"2.4.7-p4":0.0152,"2.4.7-p5":0.0132,"2.4.7-p6":0.0147,"2.4.7-p7":0.0138,"2.4.7-p8":0.0099,"2.4.7-p9":0.0078,"2.4.8":0.0165,"2.4.8-p1":0.0185,"2.4.8-p2":0.023,"2.4.8-p3":0.0188,"2.4.8-p4":0.0163,"2.4.8-p5":0.0149,"2.4.9":0.0211,"unspecified":0.2468},"confidence":0.0591},"backportWorthy":{"score":1.6902,"probabilities":{"0":0.0583,"1":0.1932,"2":0.7485},"confidence":0.4015}},"curated":{"title":"Fixes customer address file upload accepting .php files for text attributes","description":"The customer address file upload did not check whether the requested attribute's frontend_input type was file or image. Supplying a text attribute code let the uploader permit all file types, including executable files such as .php. FileUploader::validate() now returns an error when the frontend_input is not file or image.","categories":["Customer"],"author":"claude-code/opus-5.5","date":"2026-10-06","reviewedBy":null},"tests":{"2.4.8-p5":{"before":"fail","after":"pass","adapted":false,"runAt":"2026-10-06T09:20:23.104Z","releaseCommit":"870a22c63d9d9b68fa3297962e2d5d5841115814","suites":{"unit":{"before":"fail","after":"pass","runAt":"2026-10-06T09:20:23.104Z"}}},"2.4.9":{"before":"fail","after":"pass","adapted":false,"runAt":"2026-10-06T09:20:23.072Z","releaseCommit":"755e34dd689021c5165db9d35ecff74f7dc51527","suites":{"unit":{"before":"fail","after":"pass","runAt":"2026-10-06T09:20:23.072Z"}}},"2.4.7-p10":{"before":"fail","after":"pass","adapted":false,"runAt":"2026-10-06T09:29:32.251Z","releaseCommit":"72561bf80652f57cc642a03e2c9a51d74a285b14","suites":{"unit":{"before":"fail","after":"pass","runAt":"2026-10-06T09:29:32.251Z"}}}}},"_documentation":"https://magento.watch/api","_description":"Upstream fix magento2-40583 details"}