Preliminary research
Content-Type Override to Stored XSS on public objects
AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
Examines response Content-Type overrides on public object storage. MinIO accepts an anonymous override, while an attacker’s own AWS identity can satisfy S3’s signed-request requirement for a public object; serving uploaded bytes as HTML can invalidate the MIME assumptions made when the object was accepted.
Record
- Researcher
- Amirmohammad Safari
- Published by
- Voorivex
- Date
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Amirmohammad Safari, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .