Skip to content
GitLab
Menu
Projects
Groups
Snippets
Loading...
Help
Help
Support
Community forum
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in / Register
Toggle navigation
Menu
Open sidebar
chenpangpang
ComfyUI
Commits
6daf9bb2
Commit
6daf9bb2
authored
Mar 14, 2023
by
m957ymj75urz
Browse files
switch to realpath to check path traversal
parent
b1294fa4
Changes
1
Show whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
1 addition
and
1 deletion
+1
-1
nodes.py
nodes.py
+1
-1
No files found.
nodes.py
View file @
6daf9bb2
...
...
@@ -806,7 +806,7 @@ class SaveImage:
comfy_output_folder
=
os
.
path
.
join
(
os
.
path
.
dirname
(
os
.
path
.
realpath
(
__file__
)),
"output"
)
full_output_folder
=
os
.
path
.
join
(
comfy_output_folder
,
subfolder
)
if
os
.
path
.
commonpath
((
comfy_output_folder
,
os
.
path
.
abs
path
(
full_output_folder
)))
!=
comfy_output_folder
:
if
os
.
path
.
commonpath
((
comfy_output_folder
,
os
.
path
.
real
path
(
full_output_folder
)))
!=
comfy_output_folder
:
print
(
"Saving image outside the output folder is not allowed."
)
return
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
.
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment