Describe the Bug
When an image is uploaded to an upload collection without dimension adjustments or cropping, transformMain in packages/transformer-sharp/src/transformFile.ts (lines 66–70) bypasses the Sharp pipeline completely:
if (!fileIsAnimatedType && !fileHasAdjustments) {
return { status: 'continue' }
}
Because Sharp is bypassed when no resizing/formatting is specified, the raw unmodified file buffer is persisted directly to storage (S3 / Azure / local disk) and served publicly over media endpoints.
If the uploaded image was captured using a smartphone or digital camera, the stored file retains all raw EXIF metadata, including:
GPSLatitude, GPSLongitude, GPSAltitude (precise geographic coordinates of the uploader/location)
DateTimeOriginal
- Camera device serials and hardware model (
Make, Model)
This constitutes an information disclosure vulnerability (CWE-200 / GDPR Art. 5(1)(c) Data Minimization) as public consumers can extract the exact physical location where the media was captured.
Reproduction Steps
- Configure a standard Payload upload collection:
export const Media: CollectionConfig = {
slug: 'media',
upload: true,
fields: [],
}
- Upload a standard JPEG/HEIC image taken with an iPhone or Android phone containing GPS location data.
- Fetch the uploaded file from the public media URL:
curl -O http://localhost:3000/api/media/file/<filename>.jpg.
- Inspect EXIF tags with
exiftool <filename>.jpg:
- Observe that
GPS Latitude and GPS Longitude remain completely intact.
Expected Behavior
To protect user privacy and prevent sensitive location disclosure:
- Uploaded media should undergo EXIF sanitization before storage, stripping GPS and device metadata by default.
- Alternatively,
collectionUpload should expose a configurable flag (e.g., stripExif: true or stripGpsMetadata: true) allowing administrators to guarantee that public media assets do not leak uploader coordinates.
Which area(s) are affected?
Environment Info
- Payload: 3.x
- Node.js: 20.x
- Next.js: 15.x
Describe the Bug
When an image is uploaded to an
uploadcollection without dimension adjustments or cropping,transformMaininpackages/transformer-sharp/src/transformFile.ts(lines 66–70) bypasses the Sharp pipeline completely:Because Sharp is bypassed when no resizing/formatting is specified, the raw unmodified file buffer is persisted directly to storage (S3 / Azure / local disk) and served publicly over media endpoints.
If the uploaded image was captured using a smartphone or digital camera, the stored file retains all raw EXIF metadata, including:
GPSLatitude,GPSLongitude,GPSAltitude(precise geographic coordinates of the uploader/location)DateTimeOriginalMake,Model)This constitutes an information disclosure vulnerability (CWE-200 / GDPR Art. 5(1)(c) Data Minimization) as public consumers can extract the exact physical location where the media was captured.
Reproduction Steps
curl -O http://localhost:3000/api/media/file/<filename>.jpg.exiftool <filename>.jpg:GPS LatitudeandGPS Longituderemain completely intact.Expected Behavior
To protect user privacy and prevent sensitive location disclosure:
collectionUploadshould expose a configurable flag (e.g.,stripExif: trueorstripGpsMetadata: true) allowing administrators to guarantee that public media assets do not leak uploader coordinates.Which area(s) are affected?
area: corearea: uploadsEnvironment Info