When using wildcard validation to validate a given file or image field array (files.*), a user-crafted malicious request could potentially bypass the validation rules.
{
"github_reviewed": true,
"github_reviewed_at": "2025-03-05T19:09:39Z",
"nvd_published_at": "2025-03-05T19:15:39Z",
"cwe_ids": [
"CWE-155"
],
"severity": "MODERATE"
}