mirror of
https://github.com/github/codeql.git
synced 2026-04-28 10:15:14 +02:00
Update javascript/ql/lib/change-notes/2025-02-12-express-download.md
Co-authored-by: Asger F <asgerf@github.com>
This commit is contained in:
@@ -1,4 +1,4 @@
|
||||
---
|
||||
category: minorAnalysis
|
||||
---
|
||||
* Added result.download() function to ResponseDownloadAsFileSystemAccess to FileSystemReadAccess
|
||||
* The `response.download()` function in `express` is now recognized as a sink for path traversal attacks.
|
||||
Reference in New Issue
Block a user