Impact
Flask‑Reuploaded’s UploadSet.save normalizes the default path’s extension to lowercase while still honoring case‑preserving extensions supplied by a caller. The AllExcept denylist is applied after normalizing the supplied name, allowing an attacker to craft a mixed‑case extension that bypasses a lowercase denylist. The resulting file is stored in the served upload directory, and if the web server serves or executes extensions case‑insensitively, the attacker can run arbitrary code, compromising confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects jugmac00’s Flask‑Reuploaded package versions 1.5.0 up to, but not including, 1.6.0. Systems using those earlier versions that have a server path capable of case‑insensitive execution of uploaded files are at risk.
Risk and Exploitability
With a CVSS score of 7.5, the issue presents a moderate‑to‑high severity risk. The EPSS score is <1% and the vulnerability is not listed in CISA’s KEV database. Exploitation requires a user‑influenced upload endpoint, a denylist configuration, and a web server that executes or serves uploaded files case‑insensitively. Under those conditions, an attacker can upload a file that executes with the web server’s privileges, compromising confidentiality, integrity, and availability. While no public exploit is currently known, the low EPSS score indicates that exploitation is not widely anticipated, yet the vulnerability remains actionable.
OpenCVE Enrichment
Github GHSA