You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The config file can be a symlink, but it is still loaded as a TOML file and the key and value are checked, so probably no way to Arbitrary Read.
We can modify an Abitrary file via a symlink, but the modification is from the parser which doesn't allow custom format rules.
The modules are loaded via importlib_metadata.entry_points(group="mdformat.parser_extension"), which only check the PATH for python module, which prevent the creation of a malicious package.
Description of the LOTP tool
mdformat
is markdown formatting tool that can be configured we a config file.Configuration files
Documentation
https://mdformat.readthedocs.io/en/stable/users/configuration_file.html
Real-world example
Seen in the wild...
The text was updated successfully, but these errors were encountered: