From 23e43bfc60ea4bc7ff1c34dfce54e838c88ba9f3 Mon Sep 17 00:00:00 2001 From: "Alex Pooley (@zuedev)" Date: Thu, 7 May 2026 18:09:36 +0100 Subject: add comment for path trav --- usr/local/bin/git-wrapper | 1 + 1 file changed, 1 insertion(+) diff --git a/usr/local/bin/git-wrapper b/usr/local/bin/git-wrapper index bf0781b..3039d10 100644 --- a/usr/local/bin/git-wrapper +++ b/usr/local/bin/git-wrapper @@ -11,6 +11,7 @@ fi cmd=$(echo "$SSH_ORIGINAL_COMMAND" | cut -d' ' -f1) path=$(echo "$SSH_ORIGINAL_COMMAND" | cut -d"'" -f2) +# Block path traversal attempts if [[ "$path" == *..* ]]; then echo "Invalid path" >&2 exit 1 -- cgit v1.2.3