Researchers described how weak image-upload controls can let attackers submit files with benign-looking extensions such as .jpg while embedding active content that browsers may execute under the victim site’s origin context. One technique abuses browser content handling with tags such as OBJECT to force interpretation of uploaded content as Flash or other active formats, allowing a malicious file hosted on a trusted site to send authenticated requests with the victim’s cookies and read sensitive responses such as profile data or CSRF tokens. The same class of issue can also support follow-on CSRF-style actions when a logged-in user is lured to an attacker-controlled page.
Separate analysis of web applications using ImageMagick and CarrierWave showed that insecure defaults can widen the exposure by storing uploaded files and temporary cache files in publicly reachable directories, sometimes without reliable access control. The research found that obscure image formats and malformed payloads can trigger browser-side script execution when servers return incorrect or missing Content-Type headers, and that leftover cache files after validation or conversion failures may remain accessible if their URLs are guessable. Recommended defenses include validating file content as well as extensions, restricting accepted formats, serving uploads with correct MIME types, enabling X-Content-Type-Options: nosniff, and moving protected uploads and caches outside public web paths.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A 2018 security blog analyzed how web applications using ImageMagick and CarrierWave could expose uploaded and cached files in public directories, enabling access-control failures, XSS, and cache-file abuse. It also described advanced payload techniques including XV-based script execution and RGB-to-SWF transformations that could support Cross-Site Content Hijacking under certain conditions.
A 2014 blog post introduced a client-side attack technique later named Cross-Site Content Hijacking, showing how a malicious file uploaded with an allowed extension such as .jpg could be forced to load as active content and access authenticated resources on the victim site. The write-up described Flash-based exploitation, data theft of sensitive responses such as user data and CSRF tokens, and noted the naming change from Cross Domain Data Hijacking.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.