Free tools Windows power users keep installed
One-click scans. No signup required.
To accept a file with Express, submit an HTML form using method="post" and enctype="multipart/form-data", then attach Multer to the specific route that handles the upload. Parsing the request is only the first step: validate the file and form values on the server, enforce limits and authorization, and keep the file private until it is safe to use.
How to upload a file with Express
Multer is Express middleware for parsing multipart/form-data. It puts uploaded-file details on req.file or req.files and multipart text fields on req.body. The HTML file input’s name must match the field name configured in the Multer middleware.
Make the browser form multipart
<form action="/profile" method="post" enctype="multipart/form-data">
<label for="avatar">Choose an avatar</label>
<input id="avatar" name="avatar" type="file" required>
<button type="submit">Upload</button>
</form>
Here, name="avatar" corresponds to upload.single('avatar') in the route. A regular HTML form submission can also include text inputs; the server must validate those values too.
Attach Multer only to the upload route
This example accepts one file, writes it to a private staging directory, and returns 202 Accepted to indicate receipt—not that the file has passed validation or is ready to serve. The example limits are illustrative; choose limits for the actual endpoint.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
const express = require('express');
const multer = require('multer');
const app = express();
const upload = multer({
dest: 'private-uploads/',
limits: {
fileSize: 5 * 1024 * 1024,
files: 1,
fields: 8,
fieldNestingDepth: 2,
fieldArrayIndexLimit: 20
}
});
app.post('/profile', upload.single('avatar'), async (req, res, next) => {
try {
if (!req.file) {
return res.status(400).send('An avatar file is required.');
}
// Validate the file and authorize its use before accepting or publishing it.
// Keep it private while validation or processing is pending.
return res.sendStatus(202);
} catch (err) {
return next(err);
}
});
app.use((err, req, res, next) => {
if (err instanceof multer.MulterError) {
return res.status(400).send('The upload was rejected.');
}
return next(err);
});
Place the error handler after the routes. In a complete application, the route’s validation and acceptance step must be implemented before the file is used; rejected and abandoned files need a cleanup path. Avoid returning raw error details or client-supplied filenames in error responses.
Choose the right upload method
upload.single('avatar')accepts one file for that field and exposes it asreq.file.upload.array('photos', maxCount)accepts repeated files under one field, up to the configured count, and exposes them asreq.files.upload.fields([{ name: 'avatar', maxCount: 1 }, { name: 'attachments', maxCount: 3 }])accepts a known set of fields and exposes file arrays by field name inreq.files.upload.none()parses a multipart request that contains text fields but no files. Multer does not parse URL-encoded form submissions.
Do not install upload middleware globally with app.use. Restrict it to routes that expect files; otherwise a request may cause file parsing on an endpoint that was not designed to accept uploads.
Rank #2
Validate uploads instead of trusting their metadata
Every value supplied by the client is untrusted: that includes multipart text fields, file.originalname, file.mimetype, and error properties that may contain a submitted filename. A declared MIME type can be spoofed, so it is not proof of what a file contains. OWASP’s File Upload Cheat Sheet recommends layered controls rather than relying on a filename or request header alone.
- Set an allow-list. Accept only the file formats the feature needs. Check extensions as one signal, not as the sole validation method.
- Inspect content. Use content-aware checks appropriate to the accepted formats; a signature check or parser can help determine whether bytes match the claimed type. The suitable check depends on the format and the consequences of accepting malicious content.
- Consider scanning or transformation. For higher-risk formats, assess whether malware scanning or safely transforming the file before serving it is appropriate. No one check guarantees safety.
- Validate text fields and permissions. Validate form values on the server and confirm the authenticated user is allowed to upload to the target account or resource.
- Keep unapproved content private. Do not treat successful multipart parsing as approval to publish, process, or serve the file.
Never use file.originalname directly as a filesystem path. Generate a server-side identifier for storage and, if needed, retain a separately validated display name as metadata. Multer documents that the original filename comes from the request; enabling preservePath can pass path segments through in that value, which makes using it as a path especially unsafe.
Set limits that match the endpoint
Unbounded uploads and multipart fields can consume resources or contribute to denial of service. Multer’s documentation says, “Specifying the limits can help protect your site against denial of service (DoS) attacks.” Configure limits for the inputs the route actually supports.
fileSize: Maximum bytes per file. Set it to the largest file the feature needs, not an arbitrary universal default.files: Maximum number of files in the request. Keep this aligned with the route’s field definitions.fields: Maximum number of non-file fields.fieldNestingDepthandfieldArrayIndexLimit: Bound nested or indexed field structures to the depth and largest array index the application needs.
The values in the route example—5 MiB per file, one file, eight text fields, nesting depth two, and array index limit 20—are examples only, not Multer defaults or universal safe settings. Multer’s current documentation includes fieldArrayIndexLimit as a limit option.
Rank #4
Choose storage and control the file lifecycle
Multer provides disk and memory storage. Object storage is an architectural choice outside those built-in storage engines. Select storage based on expected file size and concurrency, memory pressure, access control, durability, validation workflow, retention, and how downloads will be authorized.
| Storage approach | What to consider |
|---|---|
| Disk storage | Useful when files should be written to a controlled filesystem location, but choose directory permissions and access deliberately. Plan how files move from staging after validation and how rejected, failed, or abandoned uploads are removed. |
| Memory storage | Holds each entire file as a Buffer in application memory. Multer warns that large uploads or many small files arriving quickly can exhaust memory; bound size and concurrency if using it. |
| Object storage | Evaluate private access, durability, lifecycle and retention controls, and a delivery path that authorizes each download. The right design depends on the application’s deployment architecture. |
Do not place newly uploaded files in a public static directory by default. Keep them in private staging until validation and processing succeed, then expose them only through an intentional access policy. Authorize downloads separately from uploads and define how long files are retained.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsHandle form security and deployment risks
Multipart parsing does not replace ordinary application security. Express’s production security guidance advises validating and correctly handling user input, using TLS when transmitting sensitive data, avoiding deprecated or vulnerable Express releases, and considering Helmet for security-related response headers.
Request parsing is also part of the threat surface: Node.js’s security guidance identifies denial of service from HTTP request processing as a concern for application operation. Upload limits, bounded multipart parsing, dependency maintenance, and suitable request-level controls should be considered together.
Keep Multer updated and understand the dated security notice
The live Multer documentation showed version 2.4.0 on October 4, 2026. Separately, an Express security notice published August 31, 2026 described a file-descriptor leak in Multer 2.2.0 affecting aborted disk-backed uploads and a crafted multipart field-name denial-of-service issue in versions below 2.3.0. The notice identified 2.3.0 as patched for the listed Multer issues and advised setting the field array-index limit to the largest index the application requires.
Those version and fix details describe that dated notice, not a guarantee about the latest status of every release or dependency. Keep dependency versions locked and maintained, and check current advisories and the live Multer documentation when selecting or updating a version.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

