Unauthenticated path traversal writes outside the upload root
A filename taken from a multipart request reaches Path.resolve() without normalisation. The endpoint is reachable before the auth filter, so the write happens with service credentials and no user context.
→ Path.resolve(userInput) → FileOutputStream
- The route is registered outside the authenticated filter chain.
- The verifier re-walked the path and found no containment check on any hop.
- A traversal sequence in the filename resolves outside the upload root in the same runtime configuration used in production.
- No compensating control was declared for this path in the knowledge base.