Preliminary research
Burp Suite Professional: browser-powered crawl writes attacker-controlled files
Burp Suite Professional: browser-powered crawl can write attacker-controlled files through file input handling
AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
Traces attacker-controlled file-input metadata through a browser-powered crawler into local file creation. An unchecked extension/path allows a generated upload file to escape its temporary directory, with a Windows Startup example demonstrating delayed execution at a later login under the scanner user’s permissions.
Record
- Document
- Burp Suite Professional: browser-powered crawl can write attacker-controlled files through file input handling
- Researcher
- Masahiro Kawada (kawakatz)
- Published by
- HackerOne
- Topic
- Browser
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Masahiro Kawada (kawakatz), first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .