Hunt File Upload Boundaries
Treat this card as advisory prioritization. Expected acceptance and returned storage paths are not vulnerabilities by themselves.
Workflow
- Preserve the upload method, identity, form state, media policy, and returned storage reference.
file_fetch_parserincludes fixed interpreted-file and deserialization candidates. Run it only when the complete set is authorized; preserve multipart shape and change one property.- Follow only target-returned same-origin readback. Use
xxe_boundaryonly for a typed XML or SVG parser, and keep acceptance, storage, serving, readback, and parser effects separate. - Preserve controls and evidence references. Report validated vulnerabilities independently of any challenge objective.
Evidence Gate
Confirm only a replayable policy bypass with security-relevant target-origin readback/effect, or an
independently validated parser flaw. Acceptance, extension or media disagreement, and saved paths
remain observations. Keep any contract_missing result suspected rather than promoting it.
Stop Conditions
Stop without a replay, required state, in-scope readback, clear control, or policy budget. Do not add overwrites, persistent shells, decompression bombs, or parser exhaustion; clean up canaries.