I think there is a pretty secure approach of doing it.
1) When loading a file, nothing needs to be different from the already available upload functionality. The user picks the file to load.
2) When saving a new file, nothing needs to be different from the already available download functionality. The user picks the name and the place to save it.
Only after 1 or 2 have already happened can the page request to update the file. With the same name and location. In this case, the user gets a prompt that explains the risks and asks the them to confirm the update.