Commit db03ff8
fix: add path validation for C++ file operations (PT vulnerabilities)
- convert-llama2c-to-ggml.cpp: Validate model file path before opening
- gguf-hash.cpp: Add file validation for manifest file operations
Addresses C++ path traversal vulnerabilities (CWE-23)
Co-Authored-By: Jake Cosme <[email protected]>1 parent 2e887ac commit db03ff8
File tree
2 files changed
+8
-4
lines changed- examples
- convert-llama2c-to-ggml
- gguf-hash
2 files changed
+8
-4
lines changedLines changed: 4 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
885 | 885 | | |
886 | 886 | | |
887 | 887 | | |
| 888 | + | |
| 889 | + | |
| 890 | + | |
| 891 | + | |
888 | 892 | | |
889 | 893 | | |
890 | 894 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
206 | 206 | | |
207 | 207 | | |
208 | 208 | | |
209 | | - | |
210 | | - | |
| 209 | + | |
| 210 | + | |
211 | 211 | | |
212 | 212 | | |
213 | 213 | | |
| |||
238 | 238 | | |
239 | 239 | | |
240 | 240 | | |
241 | | - | |
242 | | - | |
| 241 | + | |
| 242 | + | |
243 | 243 | | |
244 | 244 | | |
245 | 245 | | |
| |||
0 commit comments