•  
      request #45999 Ensure `extract()` is not called on untrusted inputs
    Infos
    #45999
    Thomas Gerbet (tgerbet)
    2025-12-23 12:24
    2025-12-22 16:23
    47725
    Details
    Ensure `extract()` is not called on untrusted inputs

    Spotted by Psalm taint analysis. In \Tuleap_Template is called on possibly untrusted data. This should be avoided to not give malicious users a way to influence the execution context.

    Note there is no security impact, as the existing code does not pass untrusted information.

    Other
    Empty
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Thomas Gerbet (tgerbet)
    Closed
    2025-12-23
    Attachments
    Empty
    References

    Follow-ups