Skip to content

asar not verifying filenames before passing them to minimatch #238

@Stanzilla

Description

@Stanzilla

While working on tracking down a bug with sharp, we found that asar is not verifying file names before passing them to its minimatch dependency.

electron/asar@94cb8bd/lib/asar.js#L123

isaacs/minimatch@6410ef3/minimatch.js#L128

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions