| route-pattern | /_view_fragments/voltron/pull_requests/show/:user_id/:repository/:id/pull_request_layout(.:format) |
| route-controller | voltron_pull_requests_fragments |
| route-action | pull_request_layout |
| fetch-nonce | v2:4e373311-71d5-7d65-d2f5-174ca380a047 |
| current-catalog-service-hash | ae870bc5e265a340912cde392f23dad3671a0a881730ffdadd82f2f57d81641b |
| request-id | C36E:291671:97556B:D03B32:6969EC6B |
| html-safe-nonce | 32e214f5021707dccf6597a7681c74fdc5bcbcadb9650aee18b88c919faff706 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJDMzZFOjI5MTY3MTo5NzU1NkI6RDAzQjMyOjY5NjlFQzZCIiwidmlzaXRvcl9pZCI6IjQ2MTMyMTIwNjM3NjI5NTUzMSIsInJlZ2lvbl9lZGdlIjoiaWFkIiwicmVnaW9uX3JlbmRlciI6ImlhZCJ9 |
| visitor-hmac | 05fbfbe658763fb48f8f11a7ecfbc89730b3def03bc7f4e42780484a0f1c7a84 |
| hovercard-subject-tag | pull_request:232510018 |
| github-keyboard-shortcuts | repository,pull-request-list,pull-request-conversation,pull-request-files-changed,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | ///voltron/pull_requests_fragments/pull_request_layout |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/_view_fragments/voltron/pull_requests/show/python/cpython/10627/pull_request_layout |
| twitter:image | https://opengraph.githubassets.com/d1937fd228327c415c3b5fad945de553adb8da43e1afc0b8e15206dc0f910ef3/python/cpython/pull/10627 |
| twitter:card | summary_large_image |
| og:image | https://opengraph.githubassets.com/d1937fd228327c415c3b5fad945de553adb8da43e1afc0b8e15206dc0f910ef3/python/cpython/pull/10627 |
| og:image:alt | Fixed _sanitize_params function in order to detect malicious path
Added tests
https://bugs.python.org/issue35278 |
| og:image:width | 1200 |
| og:image:height | 600 |
| og:site_name | GitHub |
| og:type | object |
| og:author:username | Thorleon |
| hostname | github.com |
| expected-hostname | github.com |
| None | 7b32f1c7c4549428ee399213e8345494fc55b5637195d3fc5f493657579235e8 |
| turbo-cache-control | no-preview |
| go-import | github.com/python/cpython git https://github.com/python/cpython.git |
| octolytics-dimension-user_id | 1525981 |
| octolytics-dimension-user_login | python |
| octolytics-dimension-repository_id | 81598961 |
| octolytics-dimension-repository_nwo | python/cpython |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 81598961 |
| octolytics-dimension-repository_network_root_nwo | python/cpython |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | bdde15ad1b403e23b08bbd89b53fbe6bdf688cad |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
| Skip to content | https://github.com/python/cpython/pull/10627#start-of-content |
|
| https://github.com/ |
|
Sign in
| https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fpython%2Fcpython%2Fpull%2F10627 |
| GitHub CopilotWrite better code with AI | https://github.com/features/copilot |
| GitHub SparkBuild and deploy intelligent apps | https://github.com/features/spark |
| GitHub ModelsManage and compare prompts | https://github.com/features/models |
| MCP RegistryNewIntegrate external tools | https://github.com/mcp |
| ActionsAutomate any workflow | https://github.com/features/actions |
| CodespacesInstant dev environments | https://github.com/features/codespaces |
| IssuesPlan and track work | https://github.com/features/issues |
| Code ReviewManage code changes | https://github.com/features/code-review |
| GitHub Advanced SecurityFind and fix vulnerabilities | https://github.com/security/advanced-security |
| Code securitySecure your code as you build | https://github.com/security/advanced-security/code-security |
| Secret protectionStop leaks before they start | https://github.com/security/advanced-security/secret-protection |
| Why GitHub | https://github.com/why-github |
| Documentation | https://docs.github.com |
| Blog | https://github.blog |
| Changelog | https://github.blog/changelog |
| Marketplace | https://github.com/marketplace |
| View all features | https://github.com/features |
| Enterprises | https://github.com/enterprise |
| Small and medium teams | https://github.com/team |
| Startups | https://github.com/enterprise/startups |
| Nonprofits | https://github.com/solutions/industry/nonprofits |
| App Modernization | https://github.com/solutions/use-case/app-modernization |
| DevSecOps | https://github.com/solutions/use-case/devsecops |
| DevOps | https://github.com/solutions/use-case/devops |
| CI/CD | https://github.com/solutions/use-case/ci-cd |
| View all use cases | https://github.com/solutions/use-case |
| Healthcare | https://github.com/solutions/industry/healthcare |
| Financial services | https://github.com/solutions/industry/financial-services |
| Manufacturing | https://github.com/solutions/industry/manufacturing |
| Government | https://github.com/solutions/industry/government |
| View all industries | https://github.com/solutions/industry |
| View all solutions | https://github.com/solutions |
| AI | https://github.com/resources/articles?topic=ai |
| Software Development | https://github.com/resources/articles?topic=software-development |
| DevOps | https://github.com/resources/articles?topic=devops |
| Security | https://github.com/resources/articles?topic=security |
| View all topics | https://github.com/resources/articles |
| Customer stories | https://github.com/customer-stories |
| Events & webinars | https://github.com/resources/events |
| Ebooks & reports | https://github.com/resources/whitepapers |
| Business insights | https://github.com/solutions/executive-insights |
| GitHub Skills | https://skills.github.com |
| Documentation | https://docs.github.com |
| Customer support | https://support.github.com |
| Community forum | https://github.com/orgs/community/discussions |
| Trust center | https://github.com/trust-center |
| Partners | https://github.com/partners |
| GitHub SponsorsFund open source developers | https://github.com/sponsors |
| Security Lab | https://securitylab.github.com |
| Maintainer Community | https://maintainers.github.com |
| Accelerator | https://github.com/accelerator |
| Archive Program | https://archiveprogram.github.com |
| Topics | https://github.com/topics |
| Trending | https://github.com/trending |
| Collections | https://github.com/collections |
| Enterprise platformAI-powered developer platform | https://github.com/enterprise |
| GitHub Advanced SecurityEnterprise-grade security features | https://github.com/security/advanced-security |
| Copilot for BusinessEnterprise-grade AI features | https://github.com/features/copilot/copilot-business |
| Premium SupportEnterprise-grade 24/7 support | https://github.com/premium-support |
| Pricing | https://github.com/pricing |
| Search syntax tips | https://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax |
| documentation | https://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax |
|
Sign in
| https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fpython%2Fcpython%2Fpull%2F10627 |
|
Sign up
| https://github.com/signup?ref_cta=Sign+up&ref_loc=header+logged+out&ref_page=%2F%3Cuser-name%3E%2F%3Crepo-name%3E%2Fvoltron%2Fpull_requests_fragments%2Fpull_request_layout&source=header-repo&source_repo=python%2Fcpython |
| Reload | https://github.com/python/cpython/pull/10627 |
| Reload | https://github.com/python/cpython/pull/10627 |
| Reload | https://github.com/python/cpython/pull/10627 |
|
python
| https://github.com/python |
| cpython | https://github.com/python/cpython |
| Please reload this page | https://github.com/python/cpython/pull/10627 |
|
Notifications
| https://github.com/login?return_to=%2Fpython%2Fcpython |
|
Fork
33.9k
| https://github.com/login?return_to=%2Fpython%2Fcpython |
|
Star
71.1k
| https://github.com/login?return_to=%2Fpython%2Fcpython |
|
Code
| https://github.com/python/cpython |
|
Issues
5k+
| https://github.com/python/cpython/issues |
|
Pull requests
2.1k
| https://github.com/python/cpython/pulls |
|
Actions
| https://github.com/python/cpython/actions |
|
Projects
31
| https://github.com/python/cpython/projects |
|
Security
Uh oh!
There was an error while loading. Please reload this page.
| https://github.com/python/cpython/security |
| Please reload this page | https://github.com/python/cpython/pull/10627 |
|
Insights
| https://github.com/python/cpython/pulse |
|
Code
| https://github.com/python/cpython |
|
Issues
| https://github.com/python/cpython/issues |
|
Pull requests
| https://github.com/python/cpython/pulls |
|
Actions
| https://github.com/python/cpython/actions |
|
Projects
| https://github.com/python/cpython/projects |
|
Security
| https://github.com/python/cpython/security |
|
Insights
| https://github.com/python/cpython/pulse |
| Sign up for GitHub
| https://github.com/signup?return_to=%2Fpython%2Fcpython%2Fissues%2Fnew%2Fchoose |
| terms of service | https://docs.github.com/terms |
| privacy statement | https://docs.github.com/privacy |
| Sign in | https://github.com/login?return_to=%2Fpython%2Fcpython%2Fissues%2Fnew%2Fchoose |
| Jump to bottom | https://github.com/python/cpython/pull/10627#issue-comment-box |
| Thorleon | https://github.com/Thorleon |
| python:main | https://github.com/python/cpython/tree/main |
| Thorleon:bpo-35278 | https://github.com/Thorleon/cpython/tree/bpo-35278 |
|
bpo-35278: Sanitize tempfile prefix to prevent directory treversal
| https://github.com/python/cpython/pull/10627#top |
| Thorleon | https://github.com/Thorleon |
| python:main | https://github.com/python/cpython/tree/main |
| Thorleon:bpo-35278 | https://github.com/Thorleon/cpython/tree/bpo-35278 |
|
Conversation
10
| https://github.com/python/cpython/pull/10627 |
|
Commits
1
| https://github.com/python/cpython/pull/10627/commits |
|
Checks
0
| https://github.com/python/cpython/pull/10627/checks |
|
Files changed
| https://github.com/python/cpython/pull/10627/files |
| Please reload this page | https://github.com/python/cpython/pull/10627 |
| https://github.co/hiddenchars |
| https://github.com/python/cpython/pull/{{ revealButtonHref }} |
|
| https://github.com/Thorleon |
| Thorleon | https://github.com/Thorleon |
| Nov 21, 2018 | https://github.com/python/cpython/pull/10627#issue-382915422 |
| Please reload this page | https://github.com/python/cpython/pull/10627 |
| https://bugs.python.org/issue35278 | https://bugs.python.org/issue35278 |
| Please reload this page | https://github.com/python/cpython/pull/10627 |
|
| https://github.com/Thorleon |
| bpo-35278: Sanitize tempfile prefix to prevent directory treversal (#… | https://github.com/python/cpython/pull/10627/commits/f27eef248d21b20f6f4cbcb6062104f805ba4a1d |
| f27eef2 | https://github.com/python/cpython/pull/10627/commits/f27eef248d21b20f6f4cbcb6062104f805ba4a1d |
| https://github.com/the-knights-who-say-ni |
| the-knights-who-say-ni | https://github.com/the-knights-who-say-ni |
| Nov 21, 2018 | https://github.com/python/cpython/pull/10627#issuecomment-440492727 |
| PSF contributor agreement | https://www.python.org/psf/contrib/contrib-form/ |
| the steps outlined in the CPython devguide | https://devguide.python.org/pullrequest/#licensing |
| check yourself | https://check-python-cla.herokuapp.com/ |
| Please reload this page | https://github.com/python/cpython/pull/10627 |
| https://github.com/the-knights-who-say-ni |
| the-knights-who-say-ni | https://github.com/the-knights-who-say-ni |
|
CLA not signed
| https://github.com/python/cpython/issues?q=state%3Aopen%20label%3A%22CLA%20not%20signed%22 |
| Nov 21, 2018 | https://github.com/python/cpython/pull/10627#event-1978879100 |
| https://github.com/bedevere-bot |
| bedevere-bot | https://github.com/bedevere-bot |
|
awaiting review
| https://github.com/python/cpython/issues?q=state%3Aopen%20label%3A%22awaiting%20review%22 |
| Nov 21, 2018 | https://github.com/python/cpython/pull/10627#event-1978879121 |
| https://github.com/the-knights-who-say-ni |
| the-knights-who-say-ni | https://github.com/the-knights-who-say-ni |
|
CLA signed
| https://github.com/python/cpython/issues?q=state%3Aopen%20label%3A%22CLA%20signed%22 |
|
CLA not signed
| https://github.com/python/cpython/issues?q=state%3Aopen%20label%3A%22CLA%20not%20signed%22 |
| Nov 21, 2018 | https://github.com/python/cpython/pull/10627#event-1980518214 |
| https://github.com/python/cpython/pull/10627 |
| YusukeEndoh | https://github.com/python/cpython/pull/10627 |
|
May 20, 2022
| https://github.com/python/cpython/pull/10627#ref-issue-1199001541 |
|
[security] directory traversal in tempfile prefix
#79459
| https://github.com/python/cpython/issues/79459 |
| https://github.com/ezio-melotti |
| ezio-melotti | https://github.com/ezio-melotti |
|
CLA signed
| https://github.com/python/cpython/issues?q=state%3Aopen%20label%3A%22CLA%20signed%22 |
| Jul 13, 2022 | https://github.com/python/cpython/pull/10627#event-6988862878 |
| https://github.com/serhiy-storchaka |
| serhiy-storchaka | https://github.com/serhiy-storchaka |
|
Mar 2, 2024
| https://github.com/python/cpython/pull/10627#pullrequestreview-1912630773 |
|
View reviewed changes
| https://github.com/python/cpython/pull/10627/files/f27eef248d21b20f6f4cbcb6062104f805ba4a1d |
| Lib/tempfile.py | https://github.com/python/cpython/pull/10627/files/f27eef248d21b20f6f4cbcb6062104f805ba4a1d#diff-6553a99f3ae04c9fc9c2349ac27037bfe3b274d5ca54d5800d9c5b5f11e29d21 |
| serhiy-storchaka | https://github.com/serhiy-storchaka |
| Mar 2, 2024 | https://github.com/python/cpython/pull/10627#discussion_r1509935132 |
| Learn more | https://docs.github.com/articles/managing-disruptive-comments/#hiding-a-comment |
| Please reload this page | https://github.com/python/cpython/pull/10627 |
| Lib/tempfile.py | https://github.com/python/cpython/pull/10627/files/f27eef248d21b20f6f4cbcb6062104f805ba4a1d#diff-6553a99f3ae04c9fc9c2349ac27037bfe3b274d5ca54d5800d9c5b5f11e29d21 |
| serhiy-storchaka | https://github.com/serhiy-storchaka |
| Mar 2, 2024 | https://github.com/python/cpython/pull/10627#discussion_r1509936098 |
| Learn more | https://docs.github.com/articles/managing-disruptive-comments/#hiding-a-comment |
| Please reload this page | https://github.com/python/cpython/pull/10627 |
| vstinner | https://github.com/vstinner |
| Mar 6, 2024 | https://github.com/python/cpython/pull/10627#discussion_r1514437504 |
| Learn more | https://docs.github.com/articles/managing-disruptive-comments/#hiding-a-comment |
| Please reload this page | https://github.com/python/cpython/pull/10627 |
| Lib/test/test_tempfile.py | https://github.com/python/cpython/pull/10627/files/f27eef248d21b20f6f4cbcb6062104f805ba4a1d#diff-cbc50394ff35aa5553e84fa01cfdda48f5215fcb60cd1ee84a0ee9682d908983 |
| serhiy-storchaka | https://github.com/serhiy-storchaka |
| Mar 2, 2024 | https://github.com/python/cpython/pull/10627#discussion_r1509936426 |
| Learn more | https://docs.github.com/articles/managing-disruptive-comments/#hiding-a-comment |
| Please reload this page | https://github.com/python/cpython/pull/10627 |
| Lib/test/test_tempfile.py | https://github.com/python/cpython/pull/10627/files/f27eef248d21b20f6f4cbcb6062104f805ba4a1d#diff-cbc50394ff35aa5553e84fa01cfdda48f5215fcb60cd1ee84a0ee9682d908983 |
| serhiy-storchaka | https://github.com/serhiy-storchaka |
| Mar 2, 2024 | https://github.com/python/cpython/pull/10627#discussion_r1509937348 |
| Learn more | https://docs.github.com/articles/managing-disruptive-comments/#hiding-a-comment |
| Please reload this page | https://github.com/python/cpython/pull/10627 |
| https://github.com/apps/bedevere-app |
| bedevere-app | https://github.com/apps/bedevere-app |
|
awaiting changes
| https://github.com/python/cpython/issues?q=state%3Aopen%20label%3A%22awaiting%20changes%22 |
|
awaiting review
| https://github.com/python/cpython/issues?q=state%3Aopen%20label%3A%22awaiting%20review%22 |
| Mar 2, 2024 | https://github.com/python/cpython/pull/10627#event-11987039142 |
| https://github.com/apps/bedevere-app |
| bedevere-app | https://github.com/apps/bedevere-app |
| Mar 2, 2024 | https://github.com/python/cpython/pull/10627#issuecomment-1974748526 |
| Please reload this page | https://github.com/python/cpython/pull/10627 |
| https://github.com/apps/github-actions |
| github-actions | https://github.com/apps/github-actions |
| Apr 13, 2025 | https://github.com/python/cpython/pull/10627#issuecomment-2799709478 |
| Please reload this page | https://github.com/python/cpython/pull/10627 |
| https://github.com/apps/github-actions |
| github-actions | https://github.com/apps/github-actions |
|
stale
| https://github.com/python/cpython/issues?q=state%3Aopen%20label%3Astale |
| Apr 13, 2025 | https://github.com/python/cpython/pull/10627#event-17237520299 |
| https://github.com/mbyrnepr2 |
| mbyrnepr2 | https://github.com/mbyrnepr2 |
| Nov 24, 2025 | https://github.com/python/cpython/pull/10627#issuecomment-3569852831 |
| @Thorleon | https://github.com/Thorleon |
| Please reload this page | https://github.com/python/cpython/pull/10627 |
| https://github.com/vstinner |
| vstinner | https://github.com/vstinner |
| Nov 24, 2025 | https://github.com/python/cpython/pull/10627#issuecomment-3569861668 |
| Please reload this page | https://github.com/python/cpython/pull/10627 |
| https://github.com/apps/github-actions |
| github-actions | https://github.com/apps/github-actions |
|
stale
| https://github.com/python/cpython/issues?q=state%3Aopen%20label%3Astale |
| Jan 1, 2026 | https://github.com/python/cpython/pull/10627#event-21816156725 |
| Sign up for free | https://github.com/join?source=comment-repo |
| Sign in to comment | https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fpython%2Fcpython%2Fpull%2F10627 |
|
| https://github.com/vstinner |
|
vstinner
| https://github.com/vstinner |
|
| https://github.com/python/cpython/pull/10627/files/f27eef248d21b20f6f4cbcb6062104f805ba4a1d |
|
| https://github.com/serhiy-storchaka |
|
serhiy-storchaka
| https://github.com/serhiy-storchaka |
|
| https://github.com/python/cpython/pull/10627/files/f27eef248d21b20f6f4cbcb6062104f805ba4a1d |
|
awaiting changes
| https://github.com/python/cpython/issues?q=state%3Aopen%20label%3A%22awaiting%20changes%22 |
| Please reload this page | https://github.com/python/cpython/pull/10627 |
|
| https://github.com/Thorleon |
|
| https://github.com/the-knights-who-say-ni |
|
| https://github.com/mbyrnepr2 |
|
| https://github.com/vstinner |
|
| https://github.com/serhiy-storchaka |
|
| https://github.com/ezio-melotti |
|
| https://github.com/bedevere-bot |
|
| https://github.com |
| Terms | https://docs.github.com/site-policy/github-terms/github-terms-of-service |
| Privacy | https://docs.github.com/site-policy/privacy-policies/github-privacy-statement |
| Security | https://github.com/security |
| Status | https://www.githubstatus.com/ |
| Community | https://github.community/ |
| Docs | https://docs.github.com/ |
| Contact | https://support.github.com?tags=dotcom-footer |