Skip to content

fix: contain backup archive extraction paths - #3500

Open
sethforprivacy wants to merge 1 commit into
devfrom
fix/cw-1607-backup-zip-slip
Open

fix: contain backup archive extraction paths#3500
sethforprivacy wants to merge 1 commit into
devfrom
fix/cw-1607-backup-zip-slip

Conversation

@sethforprivacy

Copy link
Copy Markdown
Contributor

Issue Number (if Applicable): Fixes CW-1607

Description

Adds one shared archive-entry path guard and applies it before every V1, V2, and V3 backup extraction write. POSIX and Windows absolute paths, traversal segments in either syntax, empty names, and normalized destinations outside the app directory are rejected before filesystem mutation.

Validation

  • test/core/backup_service_test.dart: 4 passed
  • Security review: no blocking findings

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant