GHSA-2rm3-333w-xvc4Medium· 5.3▾ SunlitDotVVM: Unrestricted file upload
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
All users of DotVVM with configured file upload storage are affected.
DotVVM allows anyone to upload files to the application, potentially causing denial of service by filling the disk.
Since version 4.3.15, 4.2.11 and 5.0.0-preview09, DotVVM requires all file upload request to have a cryptographic token, which is automatically generated by the FileUpload component. This means that users without access to any page with the FileUpload component cannot upload any files.
The patch also add the DotvvmConfiguration.Security.AuthorizeFileUpload option which allow you to further restrict which users can upload files.
As a workaround, you can temporarily disable file upload by removing AddUploadedFileStorage or AddDefaultTempStorage from your DotVVM configuration.
Even with the patch, we recommend configuring file upload to use a dedicated partition with limited size.
DotVVM < 4.2.11DotVVM > 4.3.0-preview01-final, < 4.3.15DotVVM >= 5.0.0-preview01-final, < 5.0.0-preview09-finalUpgrade to a patched release:
DotVVM 4.2.11DotVVM 4.3.15DotVVM 5.0.0-preview09-finalConnected by shared product, vendor, weakness, or advisory.
CVE-2026-57581Medium· 5.3DotVVM is an open source MVVM framework for web applications
CVE-2024-50623Critical· 9.8In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.
GHSA-c2g3-c4gc-w5wgHighReDoS in DotVVM routing
GHSA-c8qj-jx8j-fg2wCriticalDotVVM: Missing authorization in AuthorizeActionFilter
CVE-2026-57577High· 8.2DotVVM is an open source MVVM framework for web applications
CVE-2026-57578Critical· 9.2DotVVM is an open source MVVM framework for web applications