Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The methods accept attacker-controlled filepath values and perform writes without restricting them to the configured plans directory. If an untrusted caller can supply filepath, the code can overwrite arbitrary files accessible to the process, which can lead to data loss, tampering with application state, or clobbering sensitive configuration files.
