From 7ee8ad37f5d39b847fd1d1716457b2b08d04f522 Mon Sep 17 00:00:00 2001 From: Jakub Vrana Date: Sat, 3 Oct 2026 10:31:18 +0200 Subject: [PATCH] HtmlComposer: embeds only images inside the base path A reference in HTML that comes from untrusted content, e.g. [[../config.neon]] in a user's message, embedded any readable file into the email. A reference to a file that is missing, is not an image or is outside the base path now throws Nette\InvalidArgumentException (a missing file threw Nette\IOException before). [[...]] may be just a text, so it is left untouched in such a case. Co-Authored-By: Claude Opus 5.5 --- src/Mail/HtmlComposer.php | 40 +++++++++++++++++++++++++++++++----- tests/Mail/HtmlComposer.phpt | 35 +++++++++++++++++++++++++++++++ 2 files changed, 70 insertions(+), 5 deletions(-) diff --git a/src/Mail/HtmlComposer.php b/src/Mail/HtmlComposer.php index 3554d7c..0129eb9 100644 --- a/src/Mail/HtmlComposer.php +++ b/src/Mail/HtmlComposer.php @@ -8,8 +8,10 @@ namespace Nette\Mail; use Nette; +use Nette\Utils\FileSystem; use Nette\Utils\Strings; -use function array_map, array_reverse, explode, implode, is_string, rtrim, strlen, substr, substr_replace, trim, urldecode; +use function array_key_exists, array_map, array_reverse, explode, finfo_file, finfo_open, implode, is_file, is_string, rtrim, str_starts_with, strlen, substr, substr_replace, trim, urldecode; +use const DIRECTORY_SEPARATOR, FILEINFO_MIME_TYPE; /** @@ -31,7 +33,9 @@ public function __construct( /** * Enables embedding of local images referenced in HTML. The path is the base directory * for resolving relative image references in , , url(...) in - * style attributes/