Skip to content
This repository was archived by the owner on Feb 25, 2025. It is now read-only.
This repository was archived by the owner on Feb 25, 2025. It is now read-only.

Sanitize Zimpl models #3

@rschwarz

Description

@rschwarz

Zimpl supports reading files and printing their contents. And the scip subprocesses are started with the same user that started the zimplayground server. All files that are readible by this user can easily be leaked.

We could forbid reading from files, or check whether the path is located within some specific folder.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions