Review ID: 663aae0aba92Generated: 2026-04-14T09:38:09.875Z
CHANGES REQUESTED
1,210
Total Findings
19
Critical
1,081
High
103
Medium
7
Low
6 Tools Deployed
DiamondPlatinumGoldSilverBronzeHR RoastyFree Baseline
Free Baseline Scan — Open-source tools + Hyrex
polterguy/magic →
master @ 9df1c7f
AIAI Threat Analysis
# BRUTAL SECURITY ASSESSMENT: polterguy/magic
REAL THREATS
CREDENTIAL EXPOSURE - CRITICAL
Finding [6], [7], [9], [11], [13], [16], [18]: Hardcoded Default Database Credentials
This is genuinely dangerous. The codebase has hardcoded default database credentials scattered across the frontend application:
• vibe-coding.component.ts:339 - Database credentials in UI code
• manage-databases.component.ts:88 - Database management component with hardcoded creds
• common-error-messages.ts:16 - Error handling with embedded credentials
• backend.service.ts:114 - Core service with hardcoded database access
• openai.service.ts:125 - AI service with database credentials
• environment.prod.ts:15 - PRODUCTION environment with hardcoded credentials
• environment.ts:11 - Development environment with hardcoded credentials
Impact: An attacker who gains access to the frontend bundle (which is PUBLIC in any web application) gets direct database credentials. This is a complete compromise - they can read, modify, or delete all application data. Production credentials in frontend code means every user who loads your app gets your database password in their browser's network tab.
Attack: Download the minified JS bundle → search for credential patterns → extract database connection strings → connect directly to production database → exfiltrate all data.
---
INFRASTRUCTURE EXPOSURE - MEDIUM PRIORITY
Findings [0], [1], [2], [3], [4], [5], [8], [10], [12], [14], [15], [17]: Insecure HTTP Requests
Most of these appear to be in development configurations, documentation, and example URLs. However, [15] is concerning:
• environment.prod.json:2 - Production environment configured for HTTP
Impact: If production traffic runs over HTTP instead of HTTPS:
• All authentication tokens transmitted in cleartext
• Session hijacking via network sniffing
• Man-in-the-middle attacks
• API keys exposed in transit
The others in launch settings, README examples, and development configs are lower risk but indicate poor security hygiene.
---
WEAK CRYPTOGRAPHY - LOW PRIORITY IN CONTEXT
Findings [20], [40], [42], [44], [46], [52], [79], [87], [108], [113]: Weak or deprecated cipher
These are all in README.md files and documentation. Not in actual code. This is documentation mentioning deprecated ciphers, not implementing them. False positive pattern recognition by the scanner.
---
CODE QUALITY NOISE - NOT SECURITY ISSUES
Findings [19-118] (majority): "Changed Semgrepignore", "Localhost Base Url", "Global Access Modifiers"
This is scanner garbage. Changed .semgrepignore files and localhost references in READMEs are not attack vectors. The tool is flagging every README file as "HIGH" severity for existing. Ignore.
---
ATTACK CHAINS
Chain 1: Frontend Credential Harvest → Database Compromise
1. Attacker loads the production frontend application
2. Opens browser DevTools → Sources tab
3. Searches bundled JavaScript for database-related strings
4. Extracts hardcoded credentials from findings [6], [7], [9], [11], [13], [16], [18]
5. Uses credentials to connect directly to the production database
6. Full data breach
Risk Level: CRITICAL - This is a 5-minute attack for anyone with basic web development knowledge.
---
Chain 2: HTTP Downgrade → Session Hijacking
1. If finding [15] means production runs on HTTP (not just config file artifact)
2. Attacker on shared network (coffee shop, conference WiFi)
3. Sniffs HTTP traffic for authentication tokens
4. Replays tokens to hijack admin sessions
5. Creates backdoor accounts
Risk Level: HIGH if production actually serves HTTP, LOW if it's just a config template
---
ATTACK SURFACE SUMMARY
Actual Exploitable Issues: ~8 findings Scanner False Positives: ~1,200 findings
This scan is 99% noise. The tool flagged every README file in the repository as high severity for mentioning security concepts or containing localhost URLs.
---
VERDICT
DO NOT DEPLOY TO PRODUCTION until you fix:
MUST FIX IMMEDIATELY (before any production deployment):
1. Remove ALL hardcoded database credentials from frontend code [6, 7, 9, 11, 13, 16, 18]
- Move credentials to backend environment variables - Frontend should NEVER contain database connection strings - Rotate any credentials that were committed to version control (assume compromised) - Check Git history - if these creds were ever pushed, they're already on Have I Been Pwned
2. Verify production uses HTTPS [15]
- Enforce HSTS headers - Redirect all HTTP to HTTPS - Ensure environment.prod.json doesn't actually configure HTTP endpoints
Timeline: This is a blocker. Days, not weeks.
---
The Harsh Truth
You have 7-8 legitimate critical vulnerabilities buried in 1,200+ false positives. Your scanning tool is worse than useless - it's dangerous because it creates alert fatigue.
The hardcoded credentials in the frontend are amateur hour. This is "How to Get Hacked 101" material. If this is in production right now, assume your database is already compromised and start incident response.
The good news: Only 8 real issues. The bad news: Each one is a potential full compromise.
Ship Status: 🚫 DO NOT SHIP
---
1210 raw scanner findings — 19 critical · 1081 high · 103 medium · 7 low
▶ Raw Scanner Output — 1210 pre-cleanup findings
⚠ Pre-Cleanup Report
This is the raw, unprocessed output from all scanner agents before AI analysis. Do not use this to fix issues individually. Multiple agents attack from different angles and frequently report the same underlying vulnerability, resulting in significant duplication. Architectural issues also appear as many separate line-level findings when they require a single structural fix.

Use the Copy Fix Workflow button above to get the AI-cleaned workflow — it deduplicates findings, removes false positives, and provides actionable steps. This raw output is provided for transparency and audit purposes only.
Showing top 1000 of 1210 findings (sorted by severity). Full data available via the review API.
CRITICALHardcoded default database credentials
frontend/src/app/components/protected/dashboard/components/vibe-coding/vibe-coding.component.ts:339
[AGENTS: rules-engine]credentials
**Perspective 1:** Default database credentials are set to weak values: _APP_DB_USER='user', _APP_DB_PASS='password', _APP_DB_ROOT_PASS='rootsecretpassword'. These are common weak passwords that should not be used in production. **Perspective 2:** The environment variable _APP_EXECUTOR_SECRET is set to 'your-secret-key' which appears to be a placeholder/hardcoded value. This secret is used for inter-service communication authentication and having a predictable/default value compromises service-
Suggested Fix
Generate a cryptographically secure random secret using a CSPRNG and set it as the environment variable. For example: `_APP_EXECUTOR_SECRET=$(openssl rand -base64 32)`.
CRITICALHardcoded default database credentials
frontend/src/app/components/protected/manage/databases/manage-databases/manage-databases.component.ts:88
[AGENTS: rules-engine]credentials
**Perspective 1:** Default database credentials are set to weak values: _APP_DB_USER='user', _APP_DB_PASS='password', _APP_DB_ROOT_PASS='rootsecretpassword'. These are common weak passwords that should not be used in production. **Perspective 2:** The environment variable _APP_EXECUTOR_SECRET is set to 'your-secret-key' which appears to be a placeholder/hardcoded value. This secret is used for inter-service communication authentication and having a predictable/default value compromises service-
Suggested Fix
Generate a cryptographically secure random secret using a CSPRNG and set it as the environment variable. For example: `_APP_EXECUTOR_SECRET=$(openssl rand -base64 32)`.
CRITICALHardcoded default database credentials
frontend/src/app/helpers/common-error-messages.ts:16
[AGENTS: rules-engine]credentials
**Perspective 1:** Default database credentials are set to weak values: _APP_DB_USER='user', _APP_DB_PASS='password', _APP_DB_ROOT_PASS='rootsecretpassword'. These are common weak passwords that should not be used in production. **Perspective 2:** The environment variable _APP_EXECUTOR_SECRET is set to 'your-secret-key' which appears to be a placeholder/hardcoded value. This secret is used for inter-service communication authentication and having a predictable/default value compromises service-
Suggested Fix
Generate a cryptographically secure random secret using a CSPRNG and set it as the environment variable. For example: `_APP_EXECUTOR_SECRET=$(openssl rand -base64 32)`.
CRITICALHardcoded default database credentials
frontend/src/app/services/backend.service.ts:114
[AGENTS: rules-engine]credentials
**Perspective 1:** Default database credentials are set to weak values: _APP_DB_USER='user', _APP_DB_PASS='password', _APP_DB_ROOT_PASS='rootsecretpassword'. These are common weak passwords that should not be used in production. **Perspective 2:** The environment variable _APP_EXECUTOR_SECRET is set to 'your-secret-key' which appears to be a placeholder/hardcoded value. This secret is used for inter-service communication authentication and having a predictable/default value compromises service-
Suggested Fix
Generate a cryptographically secure random secret using a CSPRNG and set it as the environment variable. For example: `_APP_EXECUTOR_SECRET=$(openssl rand -base64 32)`.
CRITICALHardcoded default database credentials
frontend/src/app/services/openai.service.ts:125
[AGENTS: rules-engine]credentials
**Perspective 1:** Default database credentials are set to weak values: _APP_DB_USER='user', _APP_DB_PASS='password', _APP_DB_ROOT_PASS='rootsecretpassword'. These are common weak passwords that should not be used in production. **Perspective 2:** The environment variable _APP_EXECUTOR_SECRET is set to 'your-secret-key' which appears to be a placeholder/hardcoded value. This secret is used for inter-service communication authentication and having a predictable/default value compromises service-
Suggested Fix
Generate a cryptographically secure random secret using a CSPRNG and set it as the environment variable. For example: `_APP_EXECUTOR_SECRET=$(openssl rand -base64 32)`.
CRITICALHardcoded default database credentials
frontend/src/environments/environment.prod.ts:15
[AGENTS: rules-engine]credentials
**Perspective 1:** Default database credentials are set to weak values: _APP_DB_USER='user', _APP_DB_PASS='password', _APP_DB_ROOT_PASS='rootsecretpassword'. These are common weak passwords that should not be used in production. **Perspective 2:** The environment variable _APP_EXECUTOR_SECRET is set to 'your-secret-key' which appears to be a placeholder/hardcoded value. This secret is used for inter-service communication authentication and having a predictable/default value compromises service-
Suggested Fix
Generate a cryptographically secure random secret using a CSPRNG and set it as the environment variable. For example: `_APP_EXECUTOR_SECRET=$(openssl rand -base64 32)`.
CRITICALHardcoded default database credentials
frontend/src/environments/environment.ts:11
[AGENTS: rules-engine]credentials
**Perspective 1:** Default database credentials are set to weak values: _APP_DB_USER='user', _APP_DB_PASS='password', _APP_DB_ROOT_PASS='rootsecretpassword'. These are common weak passwords that should not be used in production. **Perspective 2:** The environment variable _APP_EXECUTOR_SECRET is set to 'your-secret-key' which appears to be a placeholder/hardcoded value. This secret is used for inter-service communication authentication and having a predictable/default value compromises service-
Suggested Fix
Generate a cryptographically secure random secret using a CSPRNG and set it as the environment variable. For example: `_APP_EXECUTOR_SECRET=$(openssl rand -base64 32)`.
CRITICALInsecure Http Request
backend/Properties/launchSettings.json:6
[AGENTS: rules-engine]security
The software transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Suggested Fix
See CWE-319: Cleartext Transmission of Sensitive Information
CRITICALInsecure Http Request
frontend/README.md:7
[AGENTS: rules-engine]security
The software transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Suggested Fix
See CWE-319: Cleartext Transmission of Sensitive Information
CRITICALInsecure Http Request
frontend/src/app/components/protected/common/openai/openai-prompt/openai-prompt.component.html:56
[AGENTS: rules-engine]security
The software transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Suggested Fix
See CWE-319: Cleartext Transmission of Sensitive Information
CRITICALInsecure Http Request
frontend/src/app/components/protected/core/header/header.component.ts:42
[AGENTS: rules-engine]security
The software transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Suggested Fix
See CWE-319: Cleartext Transmission of Sensitive Information
CRITICALInsecure Http Request
frontend/src/app/components/protected/create/generator/open-api-generator/open-api-generator.component.ts:47
[AGENTS: rules-engine]security
The software transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Suggested Fix
See CWE-319: Cleartext Transmission of Sensitive Information
CRITICALInsecure Http Request
frontend/src/app/components/protected/create/sql-studio/sql-studio.component.html:253
[AGENTS: rules-engine]security
The software transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Suggested Fix
See CWE-319: Cleartext Transmission of Sensitive Information
CRITICALInsecure Http Request
frontend/src/app/components/protected/manage/machine-learning/components/machine-learning-edit-history/machine-learning-edit-history.component.ts:106
[AGENTS: rules-engine]security
The software transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Suggested Fix
See CWE-319: Cleartext Transmission of Sensitive Information
CRITICALInsecure Http Request
frontend/src/app/helpers/common-error-messages.ts:28
[AGENTS: rules-engine]security
The software transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Suggested Fix
See CWE-319: Cleartext Transmission of Sensitive Information
CRITICALInsecure Http Request
frontend/src/app/services/backendsstorage.service.ts:31
[AGENTS: rules-engine]security
The software transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Suggested Fix
See CWE-319: Cleartext Transmission of Sensitive Information
CRITICALInsecure Http Request
frontend/src/assets/styles/codemirror/themes/ainiro.css:4
[AGENTS: rules-engine]security
The software transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Suggested Fix
See CWE-319: Cleartext Transmission of Sensitive Information
CRITICALInsecure Http Request
frontend/src/environments/environment.prod.json:2
[AGENTS: rules-engine]security
The software transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Suggested Fix
See CWE-319: Cleartext Transmission of Sensitive Information
CRITICALInsecure Http Request
frontend/src/environments/environment.ts:9
[AGENTS: rules-engine]security
The software transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Suggested Fix
See CWE-319: Cleartext Transmission of Sensitive Information
HIGHHardcoded database credentials
frontend/src/app/components/protected/dashboard/components/vibe-coding/vibe-coding.component.ts:339
[AGENTS: rules-engine]attack_chains
**Perspective 1:** Database credentials (_APP_DB_USER, _APP_DB_PASS, _APP_DB_ROOT_PASS) are set to default values ('user', 'password', 'rootsecretpassword'). These are weak credentials that could be easily guessed in a production environment. **Perspective 2:** Default database credentials '_APP_DB_USER=user' and '_APP_DB_PASS=password' with root access '_APP_DB_ROOT_PASS=rootsecretpassword' create a critical attack chain: 1) Attacker scans for default Appwrite deployments, 2) Uses default cred
Suggested Fix
Require unique database credentials during installation. Generate strong random passwords and avoid default values. Implement database network isolation to prevent external access.
HIGHHardcoded secrets in production code
frontend/src/app/components/protected/dashboard/components/vibe-coding/vibe-coding.component.ts:339
[AGENTS: rules-engine]api_surface
**Perspective 1:** The configuration requires hardcoded paths for SSL certificates and keys, which can expose sensitive information if not properly secured. **Perspective 2:** SSL certificate and key files must have restrictive permissions to prevent unauthorized access. **Perspective 3:** The configuration requires a hardcoded token for metrics access, which poses a security risk if the configuration file is exposed. **Perspective 4:** The Nginx configuration references SSL certificate paths
Suggested Fix
Ensure that the SSL certificate paths are set via environment variables and that the files have restrictive permissions.
HIGHHardcoded database credentials
frontend/src/app/components/protected/manage/databases/manage-databases/manage-databases.component.ts:88
[AGENTS: rules-engine]attack_chains
**Perspective 1:** Database credentials (_APP_DB_USER, _APP_DB_PASS, _APP_DB_ROOT_PASS) are set to default values ('user', 'password', 'rootsecretpassword'). These are weak credentials that could be easily guessed in a production environment. **Perspective 2:** Default database credentials '_APP_DB_USER=user' and '_APP_DB_PASS=password' with root access '_APP_DB_ROOT_PASS=rootsecretpassword' create a critical attack chain: 1) Attacker scans for default Appwrite deployments, 2) Uses default cred
Suggested Fix
Require unique database credentials during installation. Generate strong random passwords and avoid default values. Implement database network isolation to prevent external access.
HIGHHardcoded secrets in production code
frontend/src/app/components/protected/manage/databases/manage-databases/manage-databases.component.ts:88
[AGENTS: rules-engine]api_surface
**Perspective 1:** The configuration requires hardcoded paths for SSL certificates and keys, which can expose sensitive information if not properly secured. **Perspective 2:** SSL certificate and key files must have restrictive permissions to prevent unauthorized access. **Perspective 3:** The configuration requires a hardcoded token for metrics access, which poses a security risk if the configuration file is exposed. **Perspective 4:** The Nginx configuration references SSL certificate paths
Suggested Fix
Ensure that the SSL certificate paths are set via environment variables and that the files have restrictive permissions.
HIGHHardcoded database credentials
frontend/src/app/helpers/common-error-messages.ts:16
[AGENTS: rules-engine]attack_chains
**Perspective 1:** Database credentials (_APP_DB_USER, _APP_DB_PASS, _APP_DB_ROOT_PASS) are set to default values ('user', 'password', 'rootsecretpassword'). These are weak credentials that could be easily guessed in a production environment. **Perspective 2:** Default database credentials '_APP_DB_USER=user' and '_APP_DB_PASS=password' with root access '_APP_DB_ROOT_PASS=rootsecretpassword' create a critical attack chain: 1) Attacker scans for default Appwrite deployments, 2) Uses default cred
Suggested Fix
Require unique database credentials during installation. Generate strong random passwords and avoid default values. Implement database network isolation to prevent external access.
HIGHHardcoded secrets in production code
frontend/src/app/helpers/common-error-messages.ts:16
[AGENTS: rules-engine]api_surface
**Perspective 1:** The configuration requires hardcoded paths for SSL certificates and keys, which can expose sensitive information if not properly secured. **Perspective 2:** SSL certificate and key files must have restrictive permissions to prevent unauthorized access. **Perspective 3:** The configuration requires a hardcoded token for metrics access, which poses a security risk if the configuration file is exposed. **Perspective 4:** The Nginx configuration references SSL certificate paths
Suggested Fix
Ensure that the SSL certificate paths are set via environment variables and that the files have restrictive permissions.
HIGHHardcoded database credentials
frontend/src/app/services/backend.service.ts:114
[AGENTS: rules-engine]attack_chains
**Perspective 1:** Database credentials (_APP_DB_USER, _APP_DB_PASS, _APP_DB_ROOT_PASS) are set to default values ('user', 'password', 'rootsecretpassword'). These are weak credentials that could be easily guessed in a production environment. **Perspective 2:** Default database credentials '_APP_DB_USER=user' and '_APP_DB_PASS=password' with root access '_APP_DB_ROOT_PASS=rootsecretpassword' create a critical attack chain: 1) Attacker scans for default Appwrite deployments, 2) Uses default cred
Suggested Fix
Require unique database credentials during installation. Generate strong random passwords and avoid default values. Implement database network isolation to prevent external access.
HIGHHardcoded secrets in production code
frontend/src/app/services/backend.service.ts:114
[AGENTS: rules-engine]api_surface
**Perspective 1:** The configuration requires hardcoded paths for SSL certificates and keys, which can expose sensitive information if not properly secured. **Perspective 2:** SSL certificate and key files must have restrictive permissions to prevent unauthorized access. **Perspective 3:** The configuration requires a hardcoded token for metrics access, which poses a security risk if the configuration file is exposed. **Perspective 4:** The Nginx configuration references SSL certificate paths
Suggested Fix
Ensure that the SSL certificate paths are set via environment variables and that the files have restrictive permissions.
HIGHHardcoded database credentials
frontend/src/app/services/openai.service.ts:125
[AGENTS: rules-engine]attack_chains
**Perspective 1:** Database credentials (_APP_DB_USER, _APP_DB_PASS, _APP_DB_ROOT_PASS) are set to default values ('user', 'password', 'rootsecretpassword'). These are weak credentials that could be easily guessed in a production environment. **Perspective 2:** Default database credentials '_APP_DB_USER=user' and '_APP_DB_PASS=password' with root access '_APP_DB_ROOT_PASS=rootsecretpassword' create a critical attack chain: 1) Attacker scans for default Appwrite deployments, 2) Uses default cred
Suggested Fix
Require unique database credentials during installation. Generate strong random passwords and avoid default values. Implement database network isolation to prevent external access.
HIGHHardcoded secrets in production code
frontend/src/app/services/openai.service.ts:125
[AGENTS: rules-engine]api_surface
**Perspective 1:** The configuration requires hardcoded paths for SSL certificates and keys, which can expose sensitive information if not properly secured. **Perspective 2:** SSL certificate and key files must have restrictive permissions to prevent unauthorized access. **Perspective 3:** The configuration requires a hardcoded token for metrics access, which poses a security risk if the configuration file is exposed. **Perspective 4:** The Nginx configuration references SSL certificate paths
Suggested Fix
Ensure that the SSL certificate paths are set via environment variables and that the files have restrictive permissions.
HIGHHardcoded database credentials
frontend/src/environments/environment.prod.ts:15
[AGENTS: rules-engine]attack_chains
**Perspective 1:** Database credentials (_APP_DB_USER, _APP_DB_PASS, _APP_DB_ROOT_PASS) are set to default values ('user', 'password', 'rootsecretpassword'). These are weak credentials that could be easily guessed in a production environment. **Perspective 2:** Default database credentials '_APP_DB_USER=user' and '_APP_DB_PASS=password' with root access '_APP_DB_ROOT_PASS=rootsecretpassword' create a critical attack chain: 1) Attacker scans for default Appwrite deployments, 2) Uses default cred
Suggested Fix
Require unique database credentials during installation. Generate strong random passwords and avoid default values. Implement database network isolation to prevent external access.
HIGHHardcoded secrets in production code
frontend/src/environments/environment.prod.ts:15
[AGENTS: rules-engine]api_surface
**Perspective 1:** The configuration requires hardcoded paths for SSL certificates and keys, which can expose sensitive information if not properly secured. **Perspective 2:** SSL certificate and key files must have restrictive permissions to prevent unauthorized access. **Perspective 3:** The configuration requires a hardcoded token for metrics access, which poses a security risk if the configuration file is exposed. **Perspective 4:** The Nginx configuration references SSL certificate paths
Suggested Fix
Ensure that the SSL certificate paths are set via environment variables and that the files have restrictive permissions.
HIGHHardcoded database credentials
frontend/src/environments/environment.ts:11
[AGENTS: rules-engine]attack_chains
**Perspective 1:** Database credentials (_APP_DB_USER, _APP_DB_PASS, _APP_DB_ROOT_PASS) are set to default values ('user', 'password', 'rootsecretpassword'). These are weak credentials that could be easily guessed in a production environment. **Perspective 2:** Default database credentials '_APP_DB_USER=user' and '_APP_DB_PASS=password' with root access '_APP_DB_ROOT_PASS=rootsecretpassword' create a critical attack chain: 1) Attacker scans for default Appwrite deployments, 2) Uses default cred
Suggested Fix
Require unique database credentials during installation. Generate strong random passwords and avoid default values. Implement database network isolation to prevent external access.
HIGHHardcoded secrets in production code
frontend/src/environments/environment.ts:11
[AGENTS: rules-engine]api_surface
**Perspective 1:** The configuration requires hardcoded paths for SSL certificates and keys, which can expose sensitive information if not properly secured. **Perspective 2:** SSL certificate and key files must have restrictive permissions to prevent unauthorized access. **Perspective 3:** The configuration requires a hardcoded token for metrics access, which poses a security risk if the configuration file is exposed. **Perspective 4:** The Nginx configuration references SSL certificate paths
Suggested Fix
Ensure that the SSL certificate paths are set via environment variables and that the files have restrictive permissions.
HIGHIncomplete path traversal protection
frontend/src/app/access-guards/access.guard.ts:18
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/app.component.ts:9
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/create/chatbot-wizard/_module/chatbot-wizard.module.ts:11
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/create/chatbot-wizard/_module/chatbot-wizard.routing.module.ts:7
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/create/generator/_module/generator.module.ts:13
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/create/generator/_module/generator.routing.module.ts:7
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/create/generator/crud-generator/crud-generator.component.ts:21
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/create/generator/generator-base.ts:11
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/create/generator/sql-generator/sql-generator.component.ts:15
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/create/hyper-ide/components/ide-editor/ide-editor.component.ts:13
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/create/hyper-ide/components/ide-tree/ide-tree.component.ts:15
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/create/hyper-ide/module/ide.module.ts:19
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/create/hyper-ide/module/ide.routing.module.ts:8
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/create/sql-studio/_module/sql-studio-routing.module.ts:8
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/create/sql-studio/_module/sql-studio.module.ts:13
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/create/sql-studio/components/sql-view/sql-view.component.ts:18
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/dashboard/_module/dashboard-routing.module.ts:8
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/dashboard/_module/dashboard.module.ts:13
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/dashboard/dashboard.component.ts:14
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/databases/_module/databases.module.ts:11
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/databases/_module/databases.routing.module.ts:7
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/endpoints/_module/endpoints.module.ts:13
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/endpoints/_module/endpoints.routing.module.ts:8
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/endpoints/endpoints-result/endpoints-result.component.ts:13
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/endpoints/endpoints.component.ts:8
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/hyperlambda-playground/_module/hyperlambda-playground.module.ts:8
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/hyperlambda-playground/_module/hyperlambda-playground.routing.module.ts:7
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/machine-learning/_module/machine-learning.module.ts:11
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/machine-learning/_module/machine-learning.routing.module.ts:8
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/machine-learning/components/machine-learning-add-widget/machine-learning-add-widget.component.ts:13
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/machine-learning/components/machine-learning-add-workflow/machine-learning-add-workflow.component.ts:13
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/machine-learning/components/machine-learning-edit-training-snippet/machine-learning-edit-training-snippet.component.ts:14
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/machine-learning/components/machine-learning-edit-type/machine-learning-edit-type.component.ts:14
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/machine-learning/machine-learning-history/machine-learning-history.component.ts:12
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/machine-learning/machine-learning-questionnaires/machine-learning-questionnaires.component.ts:10
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/machine-learning/machine-learning-training-data/machine-learning-training-data.component.ts:14
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/machine-learning/machine-learning-types/machine-learning-types.component.ts:15
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/plugins/_module/plugins.module.ts:8
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/plugins/_module/plugins.routing.module.ts:7
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/plugins/plugins.component.ts:10
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/tasks/_module/task.module.ts:8
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/tasks/_module/task.routing.module.ts:7
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/tasks/_services/task.service.ts:10
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/tasks/components/manage-task/manage-task.component.ts:10
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/tasks/components/schedule-task/schedule-task.component.ts:9
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/user-and-roles/_module/users-roles.module.ts:11
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/user-and-roles/_module/users-roles.routing.module.ts:7
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/user-and-roles/_services/role.service.ts:10
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/user-and-roles/_services/user.service.ts:10
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/user-and-roles/components/add-extra-fields-dialog/add-extra-fields-dialog.component.ts:11
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/user-and-roles/components/change-password-dialog/change-password-dialog.component.ts:9
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/user-and-roles/components/edit-user-dialog/edit-user-dialog.component.ts:13
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/user-and-roles/components/manage-role-dialog/manage-role-dialog.component.ts:12
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/user-and-roles/components/new-user-dialog/new-user-dialog.component.ts:11
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/user-and-roles/components/shared-top-bar/shared-top-bar.component.ts:8
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/user-and-roles/roles-list/roles-list.component.ts:10
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/manage/user-and-roles/users-list/users-list.component.ts:8
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/misc/configuration/_module/config.module.ts:8
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/misc/configuration/_module/config.routing.module.ts:7
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/misc/log/_module/log.module.ts:8
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/misc/log/_module/log.routing.module.ts:7
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/misc/log/log.component.ts:12
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/setup/_module/setup.module.ts:11
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/setup/_module/setup.routing.module.ts:8
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/setup/setup.component.ts:13
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/user/generate-token-dialog/generate-token-dialog.component.ts:11
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
frontend/src/app/components/protected/user/profile/_module/profile.module.ts:8
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
Note: Fixing issues can create a domino effect — resolving one finding often surfaces new ones that were previously hidden. Multiple scan-and-fix cycles may be needed until you’re satisfied no further issues remain. How deep you go is your call.