diff options
| author | Stefan Boberg <[email protected]> | 2026-03-20 22:13:12 +0100 |
|---|---|---|
| committer | Stefan Boberg <[email protected]> | 2026-03-20 22:13:12 +0100 |
| commit | a60f50c362c3cf8378b30125096f95a178315e02 (patch) | |
| tree | f6177c014395bbaf72c0c9b664e54becfd135b77 /src/zenserver/proxy/tcpproxy.cpp | |
| parent | Rename usonpackage_forcelink to cbpackage_forcelink (diff) | |
| download | zen-a60f50c362c3cf8378b30125096f95a178315e02.tar.xz zen-a60f50c362c3cf8378b30125096f95a178315e02.zip | |
Add early path traversal validation for compute package paths
Reject absolute paths and ".." components in package file/directory
names before any filesystem operations, as a defense-in-depth layer
ahead of the existing weakly_canonical sandbox containment checks.
Diffstat (limited to 'src/zenserver/proxy/tcpproxy.cpp')
0 files changed, 0 insertions, 0 deletions