Skip to content

Potential path traversal found by codex security plugin#866

Merged
javuto merged 1 commit into
developfrom
codex-security-path-traversal
Jun 23, 2026
Merged

Potential path traversal found by codex security plugin#866
javuto merged 1 commit into
developfrom
codex-security-path-traversal

Conversation

@javuto

@javuto javuto commented Jun 23, 2026

Copy link
Copy Markdown
Collaborator

Environment package fields are stored as arbitrary strings and later joined into packages/<env>/<stored> by the public enroll package download handler. A traversal value in a non-HTTPS package field can make osctrl-tls stream a process-readable file relative to its working directory to anyone with the environment package link secret.

@javuto javuto added 🚧 bugfix Fix for an existing bug 🔐 security Security related issues labels Jun 23, 2026
@javuto javuto merged commit 888ba00 into develop Jun 23, 2026
8 checks passed
@javuto javuto deleted the codex-security-path-traversal branch June 23, 2026 13:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

🚧 bugfix Fix for an existing bug 🔐 security Security related issues

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant