[PR #27540] feat: implement file extension blacklist for upload security #31794

Closed
opened 2026-02-21 20:50:09 -05:00 by yindo · 0 comments
Owner

Original Pull Request: https://github.com/langgenius/dify/pull/27540

State: closed
Merged: Yes


Summary

Fixes #21071

This PR implements a file extension blacklist feature to prevent malicious file distribution through Dify's upload endpoints. The blacklist is configurable via environment variable UPLOAD_FILE_EXTENSION_BLACKLIST (empty by default for backward compatibility) and blocks executable files and scripts at upload time before storage.

Screenshots

Before After
image

Checklist

  • This change requires a documentation update, included: Dify Document
  • I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!)
  • I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change.
  • I've updated the documentation accordingly.
  • I ran dev/reformat(backend) and cd web && npx lint-staged(frontend) to appease the lint gods
**Original Pull Request:** https://github.com/langgenius/dify/pull/27540 **State:** closed **Merged:** Yes --- ## Summary Fixes #21071 This PR implements a file extension blacklist feature to prevent malicious file distribution through Dify's upload endpoints. The blacklist is configurable via environment variable `UPLOAD_FILE_EXTENSION_BLACKLIST` (empty by default for backward compatibility) and blocks executable files and scripts at upload time before storage. ## Screenshots | Before | After | |--------|-------| | | <img width="951" height="856" alt="image" src="https://github.com/user-attachments/assets/f9f0aa42-d699-40ba-a82a-cfb0ac69b7dd" />| ## Checklist - [ ] This change requires a documentation update, included: [Dify Document](https://github.com/langgenius/dify-docs) - [x] I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!) - [x] I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change. - [x] I've updated the documentation accordingly. - [x] I ran `dev/reformat`(backend) and `cd web && npx lint-staged`(frontend) to appease the lint gods
yindo added the pull-request label 2026-02-21 20:50:09 -05:00
yindo closed this issue 2026-02-21 20:50:09 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#31794