Description
Flask-Reuploaded provides file uploads for Flask. From 1.5.0 until 1.6.0, UploadSet.save(storage, name=...) in src/flask_uploads/flask_uploads.py applies lowercase_ext to the default upload path but uses the case-preserving extension helper for a caller-supplied name before extension_allowed evaluates an AllExcept denylist. An attacker who controls the name override can use a mixed-case dangerous extension to bypass a lowercase denylist and store the file in the served upload directory. Exploitation requires a denylist configuration, a user-influenced name override, and a deployment that resolves or executes extensions case-insensitively; pure allowlists remain protected and path containment is not bypassed. On an execution-capable upload directory, the stored file can execute with the web server's privileges and affect confidentiality, integrity, and availability. This issue is fixed in version 1.6.0.
Published: 2026-09-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution via upload handling
Action: Immediate patch
AI Analysis

Impact

Flask‑Reuploaded’s UploadSet.save normalizes the default path’s extension to lowercase while still honoring case‑preserving extensions supplied by a caller. The AllExcept denylist is applied after normalizing the supplied name, allowing an attacker to craft a mixed‑case extension that bypasses a lowercase denylist. The resulting file is stored in the served upload directory, and if the web server serves or executes extensions case‑insensitively, the attacker can run arbitrary code, compromising confidentiality, integrity, and availability.

Affected Systems

The vulnerability affects jugmac00’s Flask‑Reuploaded package versions 1.5.0 up to, but not including, 1.6.0. Systems using those earlier versions that have a server path capable of case‑insensitive execution of uploaded files are at risk.

Risk and Exploitability

With a CVSS score of 7.5, the issue presents a moderate‑to‑high severity risk. The EPSS score is <1% and the vulnerability is not listed in CISA’s KEV database. Exploitation requires a user‑influenced upload endpoint, a denylist configuration, and a web server that executes or serves uploaded files case‑insensitively. Under those conditions, an attacker can upload a file that executes with the web server’s privileges, compromising confidentiality, integrity, and availability. While no public exploit is currently known, the low EPSS score indicates that exploitation is not widely anticipated, yet the vulnerability remains actionable.

Generated by OpenCVE AI on September 20, 2026 at 23:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Flask‑Reuploaded to version 1.6.0 or later to apply the case‑folding bypass fix.
  • If upgrade is not immediately possible, remove or disable any AllExcept denylist for uploaded extensions and rely on strict allowlists that include correct case sensitivity.
  • Reconfigure the web server so that the upload directory is not executable or served directly, or move uploaded files to a non‑web‑accessible volume.

Generated by OpenCVE AI on September 20, 2026 at 23:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-937x-gpqr-72gg Flask-Reuploaded: Extension-denylist bypass via case-folding asymmetry in name-override path (incomplete-fix variant of CVE-2026-27641)
History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Jugmac00
Jugmac00 flask-reuploaded
Vendors & Products Jugmac00
Jugmac00 flask-reuploaded

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Flask-Reuploaded provides file uploads for Flask. From 1.5.0 until 1.6.0, UploadSet.save(storage, name=...) in src/flask_uploads/flask_uploads.py applies lowercase_ext to the default upload path but uses the case-preserving extension helper for a caller-supplied name before extension_allowed evaluates an AllExcept denylist. An attacker who controls the name override can use a mixed-case dangerous extension to bypass a lowercase denylist and store the file in the served upload directory. Exploitation requires a denylist configuration, a user-influenced name override, and a deployment that resolves or executes extensions case-insensitively; pure allowlists remain protected and path containment is not bypassed. On an execution-capable upload directory, the stored file can execute with the web server's privileges and affect confidentiality, integrity, and availability. This issue is fixed in version 1.6.0.
Title Flask-Reuploaded: Extension-denylist bypass via case-folding asymmetry in name-override path (incomplete-fix variant of CVE-2026-27641)
Weaknesses CWE-178
CWE-434
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Jugmac00 Flask-reuploaded
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T15:22:43.885Z

Reserved: 2026-06-15T19:15:27.343Z

Link: CVE-2026-54567

cve-icon Vulnrichment

Updated: 2026-09-16T15:22:38.691Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T18:17:53.547

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-54567

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:00:08Z

Weaknesses
  • CWE-178

    Improper Handling of Case Sensitivity

  • CWE-434

    Unrestricted Upload of File with Dangerous Type