Context-Inappropriate Capability
Medium
- Confidence
- 96% confidence
- Finding
- `load_reference_file(filename)` joins an arbitrary `filename` with `REFERENCES_DIR` and opens the result without validating that the resolved path stays داخل the intended directory. An attacker who can influence `filename` could use `../` path traversal to read other local files, potentially exposing secrets, configuration, or sensitive business data.
