UPSTREAM FIX

magento2-40583: Customer address file upload accepting .php files for text attributes

Community fix magento2-40583 merged into magento/magento2 on 2026-06-08, not in a release yet; applies cleanly to 34 releases from 2.4.6 to 2.4.9.

Fixes customer address file upload accepting .php files for text attributes edited

Pull request title
Validate frontend input type for file uploads
Pull request
magento/magento2#40583
Issues
#40795 pr-derived
Author
@SkyMulley
Merged
2026-06-08
Fixed in
no release yet
Reported on
—
Categories
Customer
Components
magento/module-customer

Labels

Area
Account
Component
Customer
Priority
P3
Severity
—
Reported on (labels)
—

Issue

Title and steps come from the upstream issue and pull request.

Description

The customer address file upload endpoint (Customer/Controller/Address/File/Upload.php) did not validate whether the requested attribute's frontend_input type was file or image before proceeding with the upload.

Steps to reproduce

1. Create a custom customer address attribute with frontend_input type of text (e.g. my_text_attribute)
2. Log in as a customer and send a POST request to /customer/address/file/upload with custom_attributes[my_text_attribute] as the file field, uploading a .php file
3. Without fix: file is accepted and saved to pub/media/customer_address/tmp/
4. With fix: request returns an error — Attribute "my_text_attribute" does not support file uploads. — and no file is written to disk
5. Verify that uploading via a legitimate file or image type attribute still works as expected

Taken from the upstream pull request.

Error signatures

Code match per tag

Each tag was checked with git apply --check against that tag's files. A clean match means the change applies; it is not a test result. Tags that already contain the fix are marked.

LineCode match per tagTests
2.4.6
2.4.6 clean 2.4.6-p1 clean 2.4.6-p2 clean 2.4.6-p3 clean 2.4.6-p4 clean 2.4.6-p5 clean 2.4.6-p6 clean 2.4.6-p7 clean 2.4.6-p8 clean 2.4.6-p9 clean 2.4.6-p10 clean 2.4.6-p11 clean 2.4.6-p12 clean 2.4.6-p13 clean 2.4.6-p14 clean 2.4.6-p15 clean
2.4.6: no test data 2.4.6-p1: no test data 2.4.6-p2: no test data 2.4.6-p3: no test data 2.4.6-p4: no test data 2.4.6-p5: no test data 2.4.6-p6: no test data 2.4.6-p7: no test data 2.4.6-p8: no test data 2.4.6-p9: no test data 2.4.6-p10: no test data 2.4.6-p11: no test data 2.4.6-p12: no test data 2.4.6-p13: no test data 2.4.6-p14: no test data 2.4.6-p15: no test data
2.4.7
2.4.7 clean 2.4.7-p1 clean 2.4.7-p2 clean 2.4.7-p3 clean 2.4.7-p4 clean 2.4.7-p5 clean 2.4.7-p6 clean 2.4.7-p7 clean 2.4.7-p8 clean 2.4.7-p9 clean 2.4.7-p10 clean
2.4.7: no test data 2.4.7-p1: no test data 2.4.7-p2: no test data 2.4.7-p3: no test data 2.4.7-p4: no test data 2.4.7-p5: no test data 2.4.7-p6: no test data 2.4.7-p7: no test data 2.4.7-p8: no test data 2.4.7-p9: no test data 2.4.7-p10: fails before, passes afterunit: fails before, passes after
2.4.8
2.4.8 clean 2.4.8-p1 clean 2.4.8-p2 clean 2.4.8-p3 clean 2.4.8-p4 clean 2.4.8-p5 clean
2.4.8: no test data 2.4.8-p1: no test data 2.4.8-p2: no test data 2.4.8-p3: no test data 2.4.8-p4: no test data 2.4.8-p5: fails before, passes afterunit: fails before, passes after
2.4.9
2.4.9 clean
2.4.9: fails before, passes afterunit: fails before, passes after

Triage

Model @cf/cloudflare/clef. Probability this is a bug fix: 95.5%. Probability it is security relevant: 90.5%.

Show the model's answers and probabilities
QuestionAnswerProbabilitiesConfidence
Change kindbugfixbugfix 92.2%, feature 2.6%, refactor 1.9%, tests_only 1.8%, dependency 0.8%, docs_only 0.7%82.1%
Areacustomercustomer 95.6%, admin 0.8%, frontend 0.8%90.3%
Reported versionunspecifiedunspecified 24.7%, 2.4.6 3.2%, 2.4.6-p1 2.4%5.9%
Scope0.36 of 20 68.6%, 1 26.4%, 2 5.0%31.4%
Risk0.23 of 20 84.3%, 1 8.7%, 2 7.1%58.4%
Worth backporting1.69 of 22 74.9%, 1 19.3%, 0 5.8%40.2%

Download

For cweagans/composer-patches, choose a version below and download the bundle. Copy its magento2-40583/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Test files are always removed; paths are relative to each package root, using the default -p1 level.

Packages (1): magento/module-customer
Bundle README (what the ZIP ships)
# magento2-40583

Community fix merged upstream into magento/magento2, adapted by magento.watch.
This is not a patch published by Adobe.

Pull request: https://github.com/magento/magento2/pull/40583
Issue: https://github.com/magento/magento2/issues/40795
Author: @SkyMulley
Source commit: bd25da414f7f8eb6fa23c8698b9c33fca4183eba
Modifications: test files and documentation removed, paths rewritten relative to each Composer package.
Licence: OSL-3.0 / AFL-3.0, as the original Magento Open Source code.
Maintainer: Łukasz Bajsarowicz (@lbajsarowicz)

Licence: Magento Open Source code under OSL-3.0 and AFL-3.0. The bundle carries the original author, source commit and the list of modifications.

Sources

Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.