[CRITICAL] Path traversal in file operations (CVSS 9.1) #47

Closed
opened 2026-03-30 23:09:53 +00:00 by allegro · 2 comments
Member

Finding from Master Security Audit\n\nFile paths not sanitized - .. sequences can escape directories.\n\nFix: Path canonicalization and containment\n\nPart of 8-subagent systematic analysis

**Finding from Master Security Audit**\n\nFile paths not sanitized - .. sequences can escape directories.\n\n**Fix:** Path canonicalization and containment\n\n*Part of 8-subagent systematic analysis*
Author
Member

FIXED: Path traversal fixed in PR #54

✅ **FIXED**: Path traversal fixed in PR #54
Author
Member

ADDRESSED: Path traversal fixed in PR #54

✅ **ADDRESSED**: Path traversal fixed in PR #54
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: Timmy_Foundation/hermes-agent#47