Unsanitized dynamic input in file path traversal
Overview
Description
Remediation Guidelines
var folder = target.replace(/^(\.\.(\/|\\|$))+/, '');if (target.indexOf('\0') !== -1) { // Handle or reject the input }const path = require("path"); var pathname = path.join("/public/", folder); if (pathname.indexOf("/public/") !== 0) { // Handle or reject the input }
References
Configuration
Last updated