Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.Sign up
Burn payloads can have Names that allow escaping cache folder #5265
Please provide answers to the following questions to help us narrow down, reproduce, and fix the problem. Fill out one section and delete the others.
If this issue is a bug:
is legal. But it "moves" the payload out of the intended cache directory.
Backslashes should be allowed to support subdirectories of the cache directory but