More path traversal fixes

This commit is contained in:
shamoon 2024-06-03 07:03:30 -07:00
parent 8a4c808ee2
commit c96e6703d3

View File

@ -47,7 +47,7 @@ export default async function handler(req, res) {
if (!mapping.segments.includes(key)) {
logger.debug("Unsupported segment: %s", key);
return res.status(403).json({ error: "Unsupported segment" });
} else if (segments[key].includes("/")) {
} else if (segments[key].includes("/") || segments[key].includes("\\") || segments[key].includes("..")) {
logger.debug("Unsupported segment value: %s", segments[key]);
return res.status(403).json({ error: "Unsupported segment value" });
}