---
id: CVE-2026-102366
title: >-
  mall4j through 4.0 contains an unrestricted file upload vulnerability in
  FileController endpoints that lack authorization checks and accept arbitrary
  file types without validation
summary: >-
  mall4j through 4.0 contains an unrestricted file upload vulnerability in
  FileController endpoints that lack authorization checks and accept arbitrary
  file types without validation. Attackers with any authenticated token can
  upload HTML o…
severity: medium
cvss: 4.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-434
vendor: gz-yami
product: mall4j
affected:
  - mall4j <= 4.0
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T00:17:03.917'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102366'
references:
  - url: >-
      https://github.com/LinYuanyi1/cve-request-poc/blob/114b3f0d149e50a7678f591bf8043399fc9ac96c/mall4j/A03_admin_file_upload_xss.py
    label: disclosure@vulncheck.com
  - url: 'https://github.com/gz-yami/mall4j'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/gz-yami/mall4j/blob/ffc672fc1aa4320ce02d0b93853bb456ae0a4dae/yami-shop-admin/src/main/java/com/yami/shop/admin/controller/FileController.java#L44-L64
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/gz-yami/mall4j/blob/ffc672fc1aa4320ce02d0b93853bb456ae0a4dae/yami-shop-service/src/main/java/com/yami/shop/service/impl/AttachFileServiceImpl.java#L62-L81
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/mall4j-through-4.0-unrestricted-file-upload-in-admin-file-endpoints
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T00:24:04.805Z'
---

## Overview

mall4j through 4.0 contains an unrestricted file upload vulnerability in FileController endpoints that lack authorization checks and accept arbitrary file types without validation. Attackers with any authenticated token can upload HTML or SVG files that execute scripts in administrator browsers when accessed from the local storage path, resulting in stored cross-site scripting.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
