HIGH SEVERITYCONFIRMED
Path traversal via platform query parameter
Package
MiroFish
Version
latest
Verified
2026-03-28
Description
MiroFish uses the `platform` query parameter directly in `os.path.join()` without sanitization. Passing `../../secret_profiles.json` as the platform value causes `os.path.normpath` to produce a path outside the intended upload directory.
Reproduction
import os
os.path.normpath(os.path.join('/uploads/simulations/sim_abc', '../../secret_profiles.json'))
# Result escapes base directory