Researchers demonstrated that common upload-validation controls can be bypassed by crafting JSON payloads that retain JSON.parse compatibility while presenting signatures or structures accepted as PDF or WEBP files. The techniques affect validation approaches including Node.js mmmagic, pdflib, the Unix file utility, and the file-type library, potentially allowing malicious gadget files to be uploaded and later consumed in client-side path traversal (CSPT), CSPT-to-CSRF, or XSS exploit chains.
A related libmagic inconsistency can cause deeply nested JSON to be classified as generic ASCII text after its JSON-recursion guard is reached, while embedded PDF-signature content near the file beginning may lead to PDF classification instead. Reported recursion limits vary substantially—about 500 nesting levels in upstream libmagic 5.46 and roughly 10 in default file 5.41 deployments on Ubuntu and macOS—requiring organizations to test their deployed validators and ensure upload checks validate both file structure and the application's downstream parsing behavior.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Maxence Schmitt published research showing how JSON-based CSPT gadgets can be crafted to bypass PDF and WEBP upload validation while remaining parseable by browsers. The write-up demonstrated bypasses affecting mmmagic, pdflib, the Unix file command, and file-type, enabling CSPT-to-CSRF and potentially XSS chains.
Research described how deeply nested JSON can exceed libmagic/file JSON parsing recursion limits and be classified as ASCII text or, when PDF signatures are embedded near the start, as a PDF. The behavior could bypass upload validation based on libmagic-derived MIME detection and route JSON content to PDF-processing components.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.