Skip to content

Prevent module name path traversal - #181

Merged
Haowen Chen (haven2world) merged 2 commits into
microsoft:mainfrom
haven2world:fix-security-issue
Sep 24, 2026
Merged

Haowen Chen (haven2world) merged 2 commits into
microsoft:mainfrom
haven2world:fix-security-issue

Conversation

@haven2world

@haven2world Haowen Chen (haven2world) commented Sep 24, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • reject module names that can be interpreted as POSIX or Windows paths before generating output files
  • prevent untrusted @overrideModuleName values from escaping the configured output directory
  • pin Mocha to 12.0.1 with the secure serialize-javascript dependency and Microsoft feed-compatible transitive dependency
  • standardize local and CI builds on Node.js 22.15.1

Security impact

This fixes a CWE-22 path traversal where a crafted @overrideModuleName JSDoc value such as ../escaped could write generated Swift or Kotlin files outside the configured output directory.

@haven2world
Haowen Chen (haven2world) merged commit 71a1ff5 into microsoft:main Sep 24, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants