-
-
Notifications
You must be signed in to change notification settings - Fork 2.8k
Closed
Labels
plugin: tmpdirrelated to the tmpdir builtin pluginrelated to the tmpdir builtin plugintype: feature-branchnew feature or API change, should be merged into features branchnew feature or API change, should be merged into features branch
Description
followup to #4202
this is an potential issue and attack vector, absolute paths are no tmpdir and escaping paths aren't either,
just normalizing would also break the world
so we should only ever accept normalized relative paths for it
Metadata
Metadata
Assignees
Labels
plugin: tmpdirrelated to the tmpdir builtin pluginrelated to the tmpdir builtin plugintype: feature-branchnew feature or API change, should be merged into features branchnew feature or API change, should be merged into features branch