fix: suppress internal path leakage in audio transcription errors (GHSA-vvxm-vxmr-624h) (#22108)

- Use os.path.basename() for filename sanitization instead of fragile blocklist

- Replace ERROR_MESSAGES.DEFAULT(e) with generic error message in both except blocks to prevent CWE-209 information disclosure

- Server-side logging via log.exception(e) is preserved for debugging
This commit is contained in:
Classic298
2026-03-01 14:44:49 -05:00
committed by GitHub
parent c83a42198d
commit 387225eb8b
+4 -4
View File
@@ -1194,8 +1194,8 @@ def transcription(
)
try:
ext = file.filename.split(".")[-1] if file.filename else ""
ext = ext.replace("/", "").replace("\\", "").replace("..", "")
safe_name = os.path.basename(file.filename) if file.filename else ""
ext = safe_name.rsplit(".", 1)[-1] if "." in safe_name else ""
id = uuid.uuid4()
@@ -1231,7 +1231,7 @@ def transcription(
raise HTTPException(
status_code=status.HTTP_400_BAD_REQUEST,
detail=ERROR_MESSAGES.DEFAULT(e),
detail="Transcription failed.",
)
except Exception as e:
@@ -1239,7 +1239,7 @@ def transcription(
raise HTTPException(
status_code=status.HTTP_400_BAD_REQUEST,
detail=ERROR_MESSAGES.DEFAULT(e),
detail="Transcription failed.",
)