Skip to content

fix(attachments): guard against dot path traversal#7

Merged
duailibe merged 2 commits intomainfrom
fix/attachments-sanitize-dotdot
Jan 16, 2026
Merged

fix(attachments): guard against dot path traversal#7
duailibe merged 2 commits intomainfrom
fix/attachments-sanitize-dotdot

Conversation

@duailibe
Copy link
Owner

@duailibe duailibe commented Jan 16, 2026

Summary

  • treat . and .. as invalid attachment filenames
  • apply the guard in both CLI and linear helper sanitizers
  • add tests to prevent regressions

Fixes #3

Testing

  • go test ./internal/cli ./internal/linear

@duailibe duailibe merged commit d77eb99 into main Jan 16, 2026
1 check passed
@duailibe duailibe deleted the fix/attachments-sanitize-dotdot branch January 16, 2026 06:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

attachments: sanitizeFileName should prevent path traversal ('.' and '..')

1 participant