Skip to content

fix: harden final upload writes and session bound export downloads - #429

Open
ibrahimelnemr wants to merge 1 commit into
devfrom
snyk/upload-download-hardening
Open

ibrahimelnemr wants to merge 1 commit into
devfrom
snyk/upload-download-hardening

Conversation

@ibrahimelnemr

Copy link
Copy Markdown
Contributor

Description

  • Resolves 5 high and 1 medium snyk vulnerabilities
  • Restrict registered export downloads to insights belonging to the current session, open validated files before responding, and sanitize attachment filenames
  • Normal upload naming and text/binary handling remain supported. Unsafe or colliding writes are rejected; missing/foreign-session downloads return 403

@ibrahimelnemr
ibrahimelnemr requested a review from a team as a code owner September 16, 2026 13:27
@snyk-io

snyk-io Bot commented Sep 16, 2026

Copy link
Copy Markdown

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant