I just patched the Mostr bridge, because apparently Deno's fetch implementation is vulnerable to fetching "file://" URIs. Thankfully I was parsing the response data before returning anything, but TIL the Deno devs implemented this as a "feature" on purpose. 🤦‍♂️ Nobody is safe from Rust.

https://gitlab.com/soapbox-pub/mostr/-/merge_requests/66

Reply to this note

Please Login to reply.

Discussion

What could be done with it?

file:///etc/passwd