From eb8db3a75b1cff1cf34af664d14756676632e2cf Mon Sep 17 00:00:00 2001 From: Jafar Akhondali Date: Tue, 30 Jul 2024 18:20:30 +0200 Subject: [PATCH] Block malicious looking requests to prevent path traversal attacks. --- ace/static.js | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/ace/static.js b/ace/static.js index fcf6a788..af681c38 100755 --- a/ace/static.js +++ b/ace/static.js @@ -31,6 +31,11 @@ if (allowSave) http.createServer(function(req, res) { var uri = unescape(url.parse(req.url).pathname); + if (path.normalize(unescape(req.url)) !== unescape(req.url)) { + res.statusCode = 403; + res.end(); + return; + } var filename = path.join(process.cwd(), uri); if (req.method == "OPTIONS") {