HIGH SEVERITYCONFIRMED

Path traversal via unvalidated simulation_id parameter

Package
MiroFish
Version
latest
Verified
2026-03-28

Description

MiroFish passes the `simulation_id` parameter directly to `os.path.join()` without validation. A crafted `simulation_id` containing `../` sequences can escape the simulations directory and access arbitrary files on the filesystem.

Reproduction

import os
os.path.normpath(os.path.join('/data/simulations', '../../uploads/projects/proj_abc'))
# Escapes to \uploads\projects\proj_abc
← All bugsScan your code →