Skip to content

Python: [Bug]: detect_media_type_from_base64 misclassifies BMP/SVG and misses MPEG-2 audio #8906

Description

Description

The magic-byte checks in detect_media_type_from_base64 (agent_framework/_types.py) are too loose in some places and too strict in others:

  • data.startswith(b"BM") returns image/bmp for any payload starting with "BM" (e.g. the text BMW is a car).
  • data.startswith(b"<?xml") returns image/svg+xml for any XML document (RSS, XHTML, plain XML).
  • Only \xff\xfb / \xff\xf3 are treated as MP3 frame sync. MPEG-2/2.5 Layer III (\xff\xf2, \xff\xe3, ...) returns None.
  • base64.b64decode is called without validate=True, so non-alphabet characters are silently discarded instead of producing the documented ValueError.

Suggested fix: for BMP, also validate the DIB header size at offset 14 (12/40/56/108/124). For SVG, require an <svg element near the start. For MP3, use the frame-sync mask b0 == 0xFF and (b1 & 0xE0) == 0xE0 plus a layer check. Decode with validate=True.

Related but separate: #8786 / PR #8787 (OpenAI clients and audio/mpeg).

Code Sample

from agent_framework import detect_media_type_from_base64 as d

d(data_bytes=b"BMW is a car")                           # 'image/bmp'
d(data_bytes=b"<?xml version='1.0'?><rss/>")            # 'image/svg+xml'
d(data_bytes=b"\xff\xf2\x90\x00" + b"\0" * 20)             # None (MPEG-2 Layer III frame)
d(data_str="iVBO!!!!Rw0KGgowMDAwMDAwMA==")      # 'image/png' (invalid chars ignored)

Error Messages / Stack Traces

Package Versions

agent-framework-core 1.19.0 (main @ 853c456)

Python Version

Python 3.11

Additional Context

Found during a code review of main @ 853c456 (2026-09-30); the repro above was run against that commit.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

agentsUsage: [Issues, PRs], Target: Single agentpythonUsage: [Issues, PRs], Target: PythonreproducedUsage: [Issues], Target: all issues that can be reproduced by the triage workflow

Type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions