Skip to content

Fix path traversal in document upload (arbitrary file write) - #388

Merged
svera merged 1 commit into
svera:mainfrom
overskye:hotfix/travelsal-filename
Sep 19, 2026
Merged

svera merged 1 commit into
svera:mainfrom
overskye:hotfix/travelsal-filename

Conversation

@overskye

Copy link
Copy Markdown
Contributor

Hi, I have a small edit :)

When uploading a document, the filename from the form was joined straight into the library path with filepath.Join, which doesn't strip .. segments. So a filename like ../../etc/cron.d/evil.epub would end up written outside the library folder entirely. Upload requires the admin role, but that's meant for managing the library, not the whole server, so this let an admin account overwrite arbitrary files anywhere the app process can write, cron jobs, systemd units, static files, whatever's writable.

Fixed by running the filename through filepath.Base before building the path, so only the bare name is used and nothing can escape the library directory. Added a test that uploads a file named with a traversal path and checks it lands inside the library folder and nothing gets written outside it, confirmed it fails on the old code and passes now.

@svera

svera commented Sep 19, 2026

Copy link
Copy Markdown
Owner

Hi @overskye , thank you for the vulnerability fix!

@svera
svera merged commit b85aa37 into svera:main Sep 19, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants