mirror of
https://github.com/HKUDS/OpenSpace.git
synced 2026-08-28 05:15:00 +00:00
- Add resolve() + is_relative_to() check in _extract_zip() to block nested traversal entries like nested/../../escape.txt - Sanitize server-provided skill name in import_skill() to prevent directory escape via malicious record metadata - Add 6 regression tests covering both attack vectors Closes #17 Co-authored-by: LeftX <xzq-xu@users.noreply.github.com> |
||
|---|---|---|
| .. | ||
| cli | ||
| __init__.py | ||
| auth.py | ||
| client.py | ||
| embedding.py | ||
| search.py | ||