From fd92d38a0dea1208442c1e8ff7b10a0ab627b1c3 Mon Sep 17 00:00:00 2001 From: "aikido-autofix[bot]" <119856028+aikido-autofix[bot]@users.noreply.github.com> Date: Fri, 11 Sep 2026 00:55:43 +0000 Subject: [PATCH] fix(security): autofix Path traversal attack possible --- src/model.rs | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/src/model.rs b/src/model.rs index d63b01c..94fbf0e 100644 --- a/src/model.rs +++ b/src/model.rs @@ -48,8 +48,16 @@ impl Model { /// @throws If the file cannot be loaded or its format is incompatible with this SDK. #[napi(factory)] pub fn from_file(env: Env, path: String) -> Result { + // Prevent path traversal attacks by rejecting paths containing '..'. + let path_ref = std::path::Path::new(&path); + if path_ref.components().any(|c| c == std::path::Component::ParentDir) { + return Err(map_err(std::io::Error::new( + std::io::ErrorKind::InvalidInput, + format!("Invalid input: {}", path_ref.display()) + ))); + } let inner = map_err(aic_sdk::Model::from_file(&path))?; - let bytes = mem::model_bytes(std::path::Path::new(&path)); + let bytes = mem::model_bytes(path_ref); Ok(Self { slot: DisposableSlot::new(env, inner, "Model", bytes),