Skip to content

Prevent path traversal#6

Open
vcwai wants to merge 1 commit intodaliworks:masterfrom
vcwai:fix-path-traversal
Open

Prevent path traversal#6
vcwai wants to merge 1 commit intodaliworks:masterfrom
vcwai:fix-path-traversal

Conversation

@vcwai
Copy link

@vcwai vcwai commented Oct 23, 2022

Ensure that model is a single path component. Otherwise, it is possible to read other files, e.g. by passing ../../var/log/xyz.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant