Open
Description
In the evaluation of sysrepo/sysrepo#3353, CodeQL seems to think there is uncontrolled data used in path expression, when there is none.
This argument to a file access function is derived from and then passed to op_export(file_path), which calls fopen(__filename).
https://github.com/sysrepo/sysrepo/pull/3353/files
step_create_input_file
is the function responsible to create a unique filename, and is untouched in this diff, and it seems to be not exploitable.
https://github.com/sysrepo/sysrepo/pull/3353/checks?check_run_id=27465095770