Is it possible for an attacker to see all files inside of /uploads?

No, there is no Koa route that exposes the uploads folder. And the only middleware that handles local uploads checks explicitly that a specific file is being requested.