HIGH SEVERITYCONFIRMED

Path traversal via platform query parameter

Package
MiroFish
Version
latest
Verified
2026-03-28

Description

MiroFish uses the `platform` query parameter directly in `os.path.join()` without sanitization. Passing `../../secret_profiles.json` as the platform value causes `os.path.normpath` to produce a path outside the intended upload directory.

Reproduction

import os
os.path.normpath(os.path.join('/uploads/simulations/sim_abc', '../../secret_profiles.json'))
# Result escapes base directory
← All bugsScan your code →