Skip to content

Path traversal in skill install: slug.replace only replaces first slash #1

@consigcody94

Description

@consigcody94

Found via code audit. src/commands/install.ts + src/lib/storage.ts:8. slug.replace('/', '-') only replaces first /. Slug like a/b/c becomes xpay-a-b/c creating directory escape.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions