Skip to content

Validate configured versions to keep installation paths inside the build directory #6

Description

@Vladyslav-Kuksiuk

The configured Embed Code version is inserted directly into download URLs and paths under build/embed-code. Values containing path traversal segments such as ../../escaped can place files outside the intended cache directory and produce malformed release URLs.

Reject invalid versions early and verify that normalized installation and checksum paths remain inside build/embed-code.

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions