add file check for Unstructured
This commit is contained in:
parent
e6ff9b259b
commit
e3ee0b4f88
|
|
@ -10,7 +10,7 @@ import {
|
||||||
import { getCredentialData, getCredentialParam, handleEscapeCharacters } from '../../../src/utils'
|
import { getCredentialData, getCredentialParam, handleEscapeCharacters } from '../../../src/utils'
|
||||||
import { getFileFromStorage, INodeOutputsValue } from '../../../src'
|
import { getFileFromStorage, INodeOutputsValue } from '../../../src'
|
||||||
import { UnstructuredLoader } from './Unstructured'
|
import { UnstructuredLoader } from './Unstructured'
|
||||||
import { isPathTraversal } from '../../../src/validator'
|
import { isPathTraversal, isUnsafeFilePath } from '../../../src/validator'
|
||||||
import sanitize from 'sanitize-filename'
|
import sanitize from 'sanitize-filename'
|
||||||
import path from 'path'
|
import path from 'path'
|
||||||
|
|
||||||
|
|
@ -565,7 +565,7 @@ class UnstructuredFile_DocumentLoaders implements INode {
|
||||||
throw new Error('Invalid file path format')
|
throw new Error('Invalid file path format')
|
||||||
}
|
}
|
||||||
|
|
||||||
if (isPathTraversal(filePath)) {
|
if (isPathTraversal(filePath) || isUnsafeFilePath(filePath)) {
|
||||||
throw new Error('Invalid path characters detected in filePath - path traversal not allowed')
|
throw new Error('Invalid path characters detected in filePath - path traversal not allowed')
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue