Skip to content

bug(uploads): raw uploaded images bypass transformer pipeline preserving sensitive EXIF GPS location metadata (CWE-200) #18629

Description

@halilyilmz

Describe the Bug

When an image is uploaded to an upload collection without dimension adjustments or cropping, transformMain in packages/transformer-sharp/src/transformFile.ts (lines 66–70) bypasses the Sharp pipeline completely:

  if (!fileIsAnimatedType && !fileHasAdjustments) {
    return { status: 'continue' }
  }

Because Sharp is bypassed when no resizing/formatting is specified, the raw unmodified file buffer is persisted directly to storage (S3 / Azure / local disk) and served publicly over media endpoints.

If the uploaded image was captured using a smartphone or digital camera, the stored file retains all raw EXIF metadata, including:

  • GPSLatitude, GPSLongitude, GPSAltitude (precise geographic coordinates of the uploader/location)
  • DateTimeOriginal
  • Camera device serials and hardware model (Make, Model)

This constitutes an information disclosure vulnerability (CWE-200 / GDPR Art. 5(1)(c) Data Minimization) as public consumers can extract the exact physical location where the media was captured.


Reproduction Steps

  1. Configure a standard Payload upload collection:
export const Media: CollectionConfig = {
  slug: 'media',
  upload: true,
  fields: [],
}
  1. Upload a standard JPEG/HEIC image taken with an iPhone or Android phone containing GPS location data.
  2. Fetch the uploaded file from the public media URL: curl -O http://localhost:3000/api/media/file/<filename>.jpg.
  3. Inspect EXIF tags with exiftool <filename>.jpg:
    • Observe that GPS Latitude and GPS Longitude remain completely intact.

Expected Behavior

To protect user privacy and prevent sensitive location disclosure:

  1. Uploaded media should undergo EXIF sanitization before storage, stripping GPS and device metadata by default.
  2. Alternatively, collectionUpload should expose a configurable flag (e.g., stripExif: true or stripGpsMetadata: true) allowing administrators to guarantee that public media assets do not leak uploader coordinates.

Which area(s) are affected?

  • area: core
  • area: uploads

Environment Info

  • Payload: 3.x
  • Node.js: 20.x
  • Next.js: 15.x

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions