Skip to content

TeXbld 0.1.2

Compare
Choose a tag to compare
@junikimm717 junikimm717 released this 03 Jul 03:29

Please upgrade immediately!

This is an emergency version which patches an extremely severe security vulnerability in which scaffolding a project allows arbitrary filesystem access.

For example, if one were to include the following in their image.toml file,

[project.files]
"mydots" = "../../../.config"

Given a certain directory structure, they could overwrite someone's dotfiles.