HIGH SEVERITYCONFIRMED
Path traversal via unvalidated simulation_id parameter
Package
MiroFish
Version
latest
Verified
2026-03-28
Description
MiroFish passes the `simulation_id` parameter directly to `os.path.join()` without validation. A crafted `simulation_id` containing `../` sequences can escape the simulations directory and access arbitrary files on the filesystem.
Reproduction
import os
os.path.normpath(os.path.join('/data/simulations', '../../uploads/projects/proj_abc'))
# Escapes to \uploads\projects\proj_abc