Skip to content

AutoFix PR#39

Open
nishfath wants to merge 1 commit into
mainfrom
qwietai/autofix/fix0008
Open

AutoFix PR#39
nishfath wants to merge 1 commit into
mainfrom
qwietai/autofix/fix0008

Conversation

@nishfath
Copy link
Copy Markdown
Owner

@nishfath nishfath commented May 20, 2026

Harness SAST and SCA AutoFix

This PR was created automatically by the Harness SAST and SCA AutoFix tool.
As long as it is open, subsequent scans and generated fixes to this same branch will be added to it as new commits.

Each commit fixes one vulnerability.

Some manual intervention might be required before merging this PR.

Project Information

Findings/Vulnerabilities Fixed

Finding 14: Directory Traversal: Attacker-controlled Data Used in File Path via request in CustomerController.saveSettings

Vulnerability Description

Attacker-Controlled input data is used as part of a file path to write a file without escaping or validation. This indicates a directory traversal vulnerability.

  • Severity: critical
  • CVSS Score: 9 (critical)
  • CWE: 22
  • Category: Directory Traversal
Commits/Files Changed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant