Skip to content

prevent path traversal via icon names - #995

Merged
MalpenZibo merged 1 commit into
MalpenZibo:mainfrom
romanstingler:fix/path-traversal-icon-names
Oct 1, 2026
Merged

MalpenZibo merged 1 commit into
MalpenZibo:mainfrom
romanstingler:fix/path-traversal-icon-names

Conversation

@romanstingler

Copy link
Copy Markdown
Collaborator

@MalpenZibo
Add is_safe_icon_name validation to reject icon names containing
.., /, or null bytes before they reach freedesktop_icons, which
joins them onto a base path. Absolute names and .. sequences could
otherwise escape the icon directory. Single dots remain allowed since
they are valid in reverse-DNS names. Includes unit tests covering
traversal attempts, separators, and null bytes.

I also want to take a deeper look at #970 I think we might need some to check this thoroughly.
Next week I might have some time to finish some of my started branches and some more code reviews.

@github-actions github-actions Bot added the bug Something isn't working label Oct 1, 2026

@MalpenZibo MalpenZibo left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

@MalpenZibo
MalpenZibo merged commit 36cfa45 into MalpenZibo:main Oct 1, 2026
5 checks passed
@romanstingler
romanstingler deleted the fix/path-traversal-icon-names branch October 1, 2026 15:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants