Skip to content

fix(trace cli): confine trace attachment reads to trace dir#40555

Merged
pavelfeldman merged 1 commit intomicrosoft:mainfrom
pavelfeldman:confine_2
May 1, 2026
Merged

fix(trace cli): confine trace attachment reads to trace dir#40555
pavelfeldman merged 1 commit intomicrosoft:mainfrom
pavelfeldman:confine_2

Conversation

@pavelfeldman
Copy link
Copy Markdown
Member

Prevents path traversal via forged attachment.sha1 metadata and zip-slip during trace extraction.

Prevents path traversal via forged attachment.sha1 metadata and
zip-slip during trace extraction.
@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented May 1, 2026

Test results for "MCP"

6863 passed, 1015 skipped


Merge workflow run.

@pavelfeldman pavelfeldman merged commit f4c9a82 into microsoft:main May 1, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants