magento2-40583: Customer address file upload accepting .php files for text attributes
Community fix magento2-40583 merged into magento/magento2 on 2026-06-08, not in a release yet; applies cleanly to 34 releases from 2.4.6 to 2.4.9.
Fixes customer address file upload accepting .php files for text attributes edited
- Pull request title
- Validate frontend input type for file uploads
- Pull request
- magento/magento2#40583
- Issues
- #40795 pr-derived
- Author
- @SkyMulley
- Merged
- 2026-06-08
- Fixed in
- no release yet
- Reported on
- —
- Categories
- Customer
- Components
- magento/module-customer
Labels
- Area
- Account
- Component
- Customer
- Priority
- P3
- Severity
- —
- Reported on (labels)
- —
Issue
Title and steps come from the upstream issue and pull request.
Description
Customer/Controller/Address/File/Upload.php) did not validate whether the requested attribute's frontend_input type was file or image before proceeding with the upload.Steps to reproduce
frontend_input type of text (e.g. my_text_attribute)2. Log in as a customer and send a
POST request to /customer/address/file/upload with custom_attributes[my_text_attribute] as the file field, uploading a .php file3. Without fix: file is accepted and saved to
pub/media/customer_address/tmp/4. With fix: request returns an error —
Attribute "my_text_attribute" does not support file uploads. — and no file is written to disk5. Verify that uploading via a legitimate
file or image type attribute still works as expectedTaken from the upstream pull request.
Error signatures
- The fix adds a check immediately after fetching the attribute metadata, throwing a `LocalizedException` if the `frontend_input` is not `file` or `image`.
Code match per tag
Each tag was checked with git apply --check against that tag's files. A clean match means the change applies; it is not a test result. Tags that already contain the fix are marked.
| Line | Code match per tag | Tests |
|---|---|---|
| 2.4.6 | 2.4.6 clean 2.4.6-p1 clean 2.4.6-p2 clean 2.4.6-p3 clean 2.4.6-p4 clean 2.4.6-p5 clean 2.4.6-p6 clean 2.4.6-p7 clean 2.4.6-p8 clean 2.4.6-p9 clean 2.4.6-p10 clean 2.4.6-p11 clean 2.4.6-p12 clean 2.4.6-p13 clean 2.4.6-p14 clean 2.4.6-p15 clean | 2.4.6: no test data 2.4.6-p1: no test data 2.4.6-p2: no test data 2.4.6-p3: no test data 2.4.6-p4: no test data 2.4.6-p5: no test data 2.4.6-p6: no test data 2.4.6-p7: no test data 2.4.6-p8: no test data 2.4.6-p9: no test data 2.4.6-p10: no test data 2.4.6-p11: no test data 2.4.6-p12: no test data 2.4.6-p13: no test data 2.4.6-p14: no test data 2.4.6-p15: no test data |
| 2.4.7 | 2.4.7 clean 2.4.7-p1 clean 2.4.7-p2 clean 2.4.7-p3 clean 2.4.7-p4 clean 2.4.7-p5 clean 2.4.7-p6 clean 2.4.7-p7 clean 2.4.7-p8 clean 2.4.7-p9 clean 2.4.7-p10 clean | 2.4.7: no test data 2.4.7-p1: no test data 2.4.7-p2: no test data 2.4.7-p3: no test data 2.4.7-p4: no test data 2.4.7-p5: no test data 2.4.7-p6: no test data 2.4.7-p7: no test data 2.4.7-p8: no test data 2.4.7-p9: no test data 2.4.7-p10: fails before, passes afterunit: fails before, passes after |
| 2.4.8 | 2.4.8 clean 2.4.8-p1 clean 2.4.8-p2 clean 2.4.8-p3 clean 2.4.8-p4 clean 2.4.8-p5 clean | 2.4.8: no test data 2.4.8-p1: no test data 2.4.8-p2: no test data 2.4.8-p3: no test data 2.4.8-p4: no test data 2.4.8-p5: fails before, passes afterunit: fails before, passes after |
| 2.4.9 | 2.4.9 clean | 2.4.9: fails before, passes afterunit: fails before, passes after |
Triage
Model @cf/cloudflare/clef. Probability this is a bug fix: 95.5%. Probability it is security relevant: 90.5%.
Show the model's answers and probabilities
| Question | Answer | Probabilities | Confidence |
|---|---|---|---|
| Change kind | bugfix | bugfix 92.2%, feature 2.6%, refactor 1.9%, tests_only 1.8%, dependency 0.8%, docs_only 0.7% | 82.1% |
| Area | customer | customer 95.6%, admin 0.8%, frontend 0.8% | 90.3% |
| Reported version | unspecified | unspecified 24.7%, 2.4.6 3.2%, 2.4.6-p1 2.4% | 5.9% |
| Scope | 0.36 of 2 | 0 68.6%, 1 26.4%, 2 5.0% | 31.4% |
| Risk | 0.23 of 2 | 0 84.3%, 1 8.7%, 2 7.1% | 58.4% |
| Worth backporting | 1.69 of 2 | 2 74.9%, 1 19.3%, 0 5.8% | 40.2% |
Download
For cweagans/composer-patches, choose a version below and download the bundle. Copy its magento2-40583/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Test files are always removed; paths are relative to each package root, using the default -p1 level.
Bundle README (what the ZIP ships)
# magento2-40583 Community fix merged upstream into magento/magento2, adapted by magento.watch. This is not a patch published by Adobe. Pull request: https://github.com/magento/magento2/pull/40583 Issue: https://github.com/magento/magento2/issues/40795 Author: @SkyMulley Source commit: bd25da414f7f8eb6fa23c8698b9c33fca4183eba Modifications: test files and documentation removed, paths rewritten relative to each Composer package. Licence: OSL-3.0 / AFL-3.0, as the original Magento Open Source code. Maintainer: Łukasz Bajsarowicz (@lbajsarowicz)
Licence: Magento Open Source code under OSL-3.0 and AFL-3.0. The bundle carries the original author, source commit and the list of modifications.
