Skip to content

Conversation

sapphi-red
Copy link
Contributor

I don't think it's possible to actually exploit this. But it's still better to avoid a real domain here.

I didn't reject a URL without the base part as I guess this function need to accept path-only URLs (e.g. /foo).

fixes #31

@Ryderpro
Copy link

Ryderpro commented Oct 7, 2025

@williamstein
Copy link
Contributor

Nice -- I totally agree.

@williamstein williamstein merged commit f7f1ff9 into sagemathinc:main Oct 7, 2025
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Security: Empty target defaults to external dummy.org domain

3 participants