doc: clarify fileURLToPath security considerations · nodejs/node@9a9bed9 · GitHub
Skip to content

Commit 9a9bed9

Browse files
committed
doc: clarify fileURLToPath security considerations
Add clarification that fileURLToPath() decodes encoded dot-segments (%2e%2e) which are normalized as path traversal. Applications must perform their own path validation to prevent directory traversal attacks. Also applies to fileURLToPathBuffer(). PR-URL: #60887 Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com> Reviewed-By: Luigi Pinca <luigipinca@gmail.com> Reviewed-By: Colin Ihrig <cjihrig@gmail.com> Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
1 parent ac367b3 commit 9a9bed9

1 file changed

Lines changed: 23 additions & 0 deletions

File tree

doc/api/url.md

Lines changed: 23 additions & 0 deletions

0 commit comments

Comments
 (0)