# Is it safe to allow HTML uploads?

**URL:** <https://meta.discourse.org/t/is-it-safe-to-allow-html-uploads/136797>\
**Category:** Support\
**Created:** [December 21, 2019, 10:43pm UTC](https://meta.discourse.org/t/is-it-safe-to-allow-html-uploads/136797 "2019-12-21T22:43:40Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![Alex\_P](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/alex_p/32/163548_2.png) [@Alex\_P](https://meta.discourse.org/u/Alex_P)\
**Post date:** [December 21, 2019, 10:43pm UTC](https://meta.discourse.org/t/is-it-safe-to-allow-html-uploads/136797/1 "2019-12-21T22:43:40Z")

</div>

As far as I can see the uploaded HTMLs are just downloaded as normal files (e.g. archives or PDFs), so it’s up to the user and the browser settings (open automatically after download, …) whether to open them.

But this topic mentions something about XSS…

> [@Security checks on uploads](https://meta.discourse.org/t/security-checks-on-uploads/26839/20):
>
> If I can upload an HTML page I can do what’s called a Cross Site Scripting (XSS) attack, as some browsers will render gifs as HTML. [Neal Poole from Facebook wrote about a Wordpress vuln like this back in 2011](https://nealpoole.com/blog/2011/04/file-upload-xss-vulnerability-in-wordpress/) The HTML file could have javascript in it, which I could use to do bad things. Again, I’m not a security researcher (though that’s what our community is made up of), so I can’t speak at length about XSS or test this thoroughly. I’m just wondering if you guys do anything to check headers o…

As I understand there is no way to interact with the Discourse page from the downloaded file?  
So the worst it can do is show some kind of phishing content.

---

_[View the full topic](https://meta.discourse.org/t/is-it-safe-to-allow-html-uploads/136797)._
