Skip to content

fix(beam): prevent path traversal via client-controlled root in /api/browse#4

Merged
Arul- merged 3 commits into
portel-dev:mainfrom
sebastiondev:fix/cwe22-api-browse-controlled-6d39
Jun 7, 2026
Merged

fix(beam): prevent path traversal via client-controlled root in /api/browse#4
Arul- merged 3 commits into
portel-dev:mainfrom
sebastiondev:fix/cwe22-api-browse-controlled-6d39

fix(beam): check boundary before realpath to avoid ENOENT leaking pat…

6682d92
Select commit
Loading
Failed to load commit list.

Workflow runs completed with no jobs