mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-09-30 19:21:33 +02:00
Archive upload endpoints used the client-supplied filename directly in file paths, allowing an authenticated attacker to write files outside the intended directory (e.g. ../../evil.3mf bypasses the .3mf extension check). Added _safe_filename() helper that normalizes backslashes and extracts the basename before constructing paths.