lack of escaping of filename in content-disposition FileAttachment()
is vulnerable to Reflect File Download
#84
Annotations
2 warnings
Run octokit/graphql-action@v2.x
Unexpected input(s) 'projectid', 'itemid', 'fieldid', 'value', valid inputs are ['query', 'mediaType', 'variables']
|
Run octokit/graphql-action@v2.x
Unexpected input(s) 'projectid', 'contentid', valid inputs are ['query', 'mediaType', 'variables']
|
Loading