Skip to content

fix: prevent share path traversal#1786

Open
MaxMiksa wants to merge 1 commit intobytedance:mainfrom
MaxMiksa:fix-share-path-traversal
Open

fix: prevent share path traversal#1786
MaxMiksa wants to merge 1 commit intobytedance:mainfrom
MaxMiksa:fix-share-path-traversal

Conversation

@MaxMiksa
Copy link

@MaxMiksa MaxMiksa commented Jan 17, 2026

Summary

  • Validate share image paths stay within workspace boundaries
  • Reject path traversal and symlink escapes in agent-server and agent-server-next
  • Add traversal regression tests

Testing

  • Not run (no local runtime configured)

Related Issue

@netlify
Copy link

netlify bot commented Jan 17, 2026

Deploy Preview for agent-tars-docs ready!

Name Link
🔨 Latest commit 86bcd19
🔍 Latest deploy log https://app.netlify.com/projects/agent-tars-docs/deploys/696c1d47ff35f60009d8890e
😎 Deploy Preview https://deploy-preview-1786--agent-tars-docs.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@netlify
Copy link

netlify bot commented Jan 17, 2026

Deploy Preview for tarko ready!

Name Link
🔨 Latest commit 86bcd19
🔍 Latest deploy log https://app.netlify.com/projects/tarko/deploys/696c1d4703f1a30007fa410a
😎 Deploy Preview https://deploy-preview-1786--tarko.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@CLAassistant
Copy link

CLAassistant commented Jan 17, 2026

CLA assistant check
All committers have signed the CLA.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Security tracking: share path traversal hardening

2 participants