CVE-2026-33193: Cve 2026 33193 Multipart Mime Type Spoofing Stored Xss

Client-supplied MIME type ($FILE.mimetype) from a multipart upload is stored or returned without server-side derivation from the file name or extension. An attacker can spoof the Content-Type header in the multipart request to inject arbitrary MIME types (e.g., text/html), which the server stores and later uses as the HTTP response Content-Type header, causi

Provally CuratedPublic repositoryMediumHigh confidenceVerifiedApache-2.0TS
greprules fetch cve-2026-33193-cve-2026-33193-multipart-mime-type-spoofing-stored-xss --engine opengrep

Description

Client-supplied MIME type ($FILE.mimetype) from a multipart upload is stored or returned without server-side derivation from the file name or extension. An attacker can spoof the Content-Type header in the multipart request to inject arbitrary MIME types (e.g., text/html), which the server stores and later uses as the HTTP response Content-Type header, causi