CWE Rule 434
R2026bDescription
Unrestricted Upload of File with Dangerous Type
Polyspace Implementation
The rule checker checks for Use of unsanitized tainted filename.
Examples
Unrestricted upload of file with dangerous type occurs when a filename obtained from an untrusted source reaches a sensitive function such as fopen or system without validation or sanitization. The checker requires you to specify taint sources and sanitizers in a -code-behavior-specifications datalog file.
Using tainted file names with sensitive functions without sanitizing them can result in system vulnerabilities. For example:
An attacker can upload files with executable extensions (such as
.shor.php) and trigger their execution on a server.An attacker can use path traversal sequences in filenames to overwrite critical system files.
Malicious files stored in web-accessible directories can be served to other users.
Sanitize uploaded filenames before using them with sensitive functions:
Validate file extensions against an allowlist of permitted types.
Verify file content matches the declared type.
Store uploaded files outside executable directories.
Specify the sanitizing function in your -code-behavior-specifications file so that Polyspace® recognizes the data as sanitized after the function call.
fopen() and system()In this example, the function get_uploaded_filename is a taint
source. The tainted filename flows to fopen and
system without sanitization. Polyspace reports violations.
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
extern const char *get_uploaded_filename(void);
extern const unsigned char *get_uploaded_content(size_t *len);
static const char *upload_dir(void) { return "uploads"; }
int save_upload(void)
{
const char *name = get_uploaded_filename();
const unsigned char *buf;
size_t len;
char path[128];
FILE *fp;
buf = get_uploaded_content(&len);
snprintf(path, sizeof(path), "%s/%s", upload_dir(), name);
fp = fopen(path, "wb"); // Noncompliant
if (!fp) return 0;
fwrite(buf, 1U, len, fp);
fclose(fp);
system(path); // Noncompliant
return 1;
}To specify the function as a taint source, specify this datalog code as a
.dl file input to the option -code-behavior-specifications:
.include "models/interfaces/cwe434.dl"
Custom_CWE_434.Basic.taintSource(
"get_uploaded_filename",
$OutReturnDeref(),
"User-controlled upload filename!"
).
Alias.Basic.allocates("get_uploaded_filename", $OutReturnValue()).
Custom_CWE_434.specificationFile(__FILE__).
This datalog code specifies that the filename returned by
get_uploaded_filename is tainted. It flows through
snprintf into path, which is then passed to
fopen and system. An attacker can supply a
malicious filename such as "malicious.sh" to execute arbitrary code on
the server.
One possible correction is to pass the filename through a sanitizing function that generates a
safe server-side name. In this code, the tainted file name is sanitized using the function
make_server_filename.
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
extern const char *get_uploaded_filename(void);
extern const unsigned char *get_uploaded_content(size_t *len);
extern void make_server_filename(char *out, size_t out_sz, const char *ext);
static const char *upload_dir(void) { return "data_uploads"; }
static int has_allowed_ext(const char *name)
{
const char *dot = strrchr(name, '.');
if (!dot || dot == name) return 0;
return (strcmp(dot, ".png") == 0 || strcmp(dot, ".txt") == 0);
}
int save_upload(void)
{
const char *name = get_uploaded_filename();
const unsigned char *buf;
size_t len;
char safe_name[64];
char path[128];
const char *dot;
FILE *fp;
if (!has_allowed_ext(name)) return 0;
dot = strrchr(name, '.');
make_server_filename(safe_name, sizeof(safe_name), dot);
buf = get_uploaded_content(&len);
snprintf(path, sizeof(path), "%s/%s", upload_dir(), safe_name);
fp = fopen(path, "wb"); // Compliant
if (!fp) return 0;
fwrite(buf, 1U, len, fp);
fclose(fp);
return 1;
}To specify the sanitizing function, specify this datalog code as a
.dl file input to the option -code-behavior-specifications
.include "models/interfaces/cwe434.dl"
Custom_CWE_434.Basic.taintSource(
"get_uploaded_filename",
$OutReturnDeref(),
"User-controlled upload filename!"
).
Alias.Basic.allocates("get_uploaded_filename", $OutReturnValue()).
Custom_CWE_434.Basic.sanitizing(
"make_server_filename",
$OutParameterDeref(0)
).
Custom_CWE_434.specificationFile(__FILE__).
Check Information
| Category: Handler Errors |
PQL Name: std.cwe_native.R434 |
Version History
Introduced in R2026b
MATLAB Command
You clicked a link that corresponds to this MATLAB command:
Run the command by entering it in the MATLAB Command Window. Web browsers do not support MATLAB commands.
Select a Web Site
Choose a web site to get translated content where available and see local events and offers. Based on your location, we recommend that you select: .
You can also select a web site from the following list
How to Get Best Site Performance
Select the China site (in Chinese or English) for best site performance. Other MathWorks country sites are not optimized for visits from your location.
Americas
- América Latina (Español)
- Canada (English)
- United States (English)
Europe
- Belgium (English)
- Denmark (English)
- Deutschland (Deutsch)
- España (Español)
- Finland (English)
- France (Français)
- Ireland (English)
- Italia (Italiano)
- Luxembourg (English)
- Netherlands (English)
- Norway (English)
- Österreich (Deutsch)
- Portugal (English)
- Sweden (English)
- Switzerland
- United Kingdom (English)