You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
PR #2107 by johnpippett: Security: fix remote file write and shell injection in template extensions
Fixed a remote arbitrary file write vulnerability by disabling automatic application of file changes when running in API mode, preventing unsupervised writes triggered through the REST API's PatternName input.
Replaced the weak strings.Contains(path, "..") check in the file manager with proper path containment validation that rejects absolute paths and confirms resolved paths stay within the project root.
Hardened the path containment check in ApplyFileChanges by using filepath.Rel, correctly handling edge cases such as a project root of /.
Consolidated path validation in ParseFileChanges and ApplyFileChanges to a single filepath.IsLocal call, which rejects absolute paths, empty paths, directory traversal, and Windows reserved names.
Added a regression test that fails if the path containment guard is removed.