Skip to content

Add Remotion file write fix reference#8274

Open
cookesan wants to merge 1 commit into
github:cookesan/advisory-improvement-8274from
cookesan:remotion-g6pc-fix-reference
Open

Add Remotion file write fix reference#8274
cookesan wants to merge 1 commit into
github:cookesan/advisory-improvement-8274from
cookesan:remotion-g6pc-fix-reference

Conversation

@cookesan

Copy link
Copy Markdown

Adds the upstream merge commit that fixed Remotion Studio filesystem endpoints for GHSA-g6pc-6676-c23j.

Evidence checked:

  • @remotion/studio: Better protect endpoints touching filesystem remotion-dev/remotion#6378 is merged as e3fcb3382057bb0bf1b0128a4f40c557ece7527a.
  • v4.0.410 includes that merge commit and lists the endpoint-hardening PR.
  • npm package archives for remotion, @remotion/cli, @remotion/studio-server, and @remotion/studio 4.0.410 match registry shasums; the fixed archives include the scoped add-asset route, same-origin check, and shell-free Windows file-open path.

@github-actions github-actions Bot changed the base branch from main to cookesan/advisory-improvement-8274 June 29, 2026 11:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant