CVE-2025-70849: Generic Stored Xss Missing Content Type
Serving file content directly to an HTTP response without explicitly setting a `Content-Type` or `Content-Security-Policy` header can lead to Stored Cross-Site Scripting (XSS). Unauthenticated users who upload malicious HTML or JavaScript content may achieve XSS execution when browsers perform MIME-sniffing and render it as HTML. Explicitly configure headers
greprules fetch cve-2025-70849-generic-stored-xss-missing-content-type --engine opengrepDescription
Serving file content directly to an HTTP response without explicitly setting a `Content-Type` or `Content-Security-Policy` header can lead to Stored Cross-Site Scripting (XSS). Unauthenticated users who upload malicious HTML or JavaScript content may achieve XSS execution when browsers perform MIME-sniffing and render it as HTML. Explicitly configure headers
Community feedback
0 signals from signed-in users.
- Useful
- 0
- False positive
- 0
- Metadata
- 0