Files
google-labs-jules[bot] d7ecd2cdfc 🛡️ Sentinel: [MEDIUM] Fix input validation on file upload
🚨 Severity: MEDIUM
💡 Vulnerability: Missing input validation on file upload allowed non-image files to be stored in settings.
🎯 Impact: Storing non-image data (potentially malicious payloads) in settings storage, which could be used for further exploitation or DoS.
🔧 Fix:
- Added strict file type validation (`image/*`) in `handleFileUpload`.
- Updated `optimizeImage` to return `null` if image loading fails, ensuring invalid data is not stored.
- Added user alerts for invalid file types or processing failures.
✅ Verification:
- Added `src/__tests__/image-security.test.ts` to verify `optimizeImage` fails securely.
- Verified with `pnpm test`.
2026-01-17 19:52:29 +00:00
..
2026-01-16 20:10:07 +00:00