Skip to content

Commit 253882c

Browse files
Kwstubbsasgerf
andauthored
Update javascript/ql/lib/change-notes/2025-02-12-express-download.md
Co-authored-by: Asger F <[email protected]>
1 parent f5521ca commit 253882c

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
11
---
22
category: minorAnalysis
33
---
4-
* Added result.download() function to ResponseDownloadAsFileSystemAccess to FileSystemReadAccess
4+
* The `response.download()` function in `express` is now recognized as a sink for path traversal attacks.

0 commit comments

Comments
 (0)