-
Notifications
You must be signed in to change notification settings - Fork 93
Open
Description
Line 168 in 614a799
| _jsvu_ downloads files over HTTPS, and only uses URLs that are controlled by the creators of the JavaScript engine or, in the case of JavaScriptCore on Linux, the port maintainers. |
only uses URLs that are controlled by the creators of the JavaScript engine or, in the case of JavaScriptCore on Linux, the port maintainers.
This is not true
And will attempt to create a /GoogleChromeLabs (controlled) dir in the fs
Please add both (1) input validation and (2) asserts before downloading / fs ops that we are operating in the correct allowed locations
Also see #159
Likely isn't worth a private security report. Those are not enabled in this repo settings anyway
Metadata
Metadata
Assignees
Labels
No labels