mirror of
https://github.com/Shiva108/ai-llm-red-team-handbook.git
synced 2026-09-23 01:40:48 +02:00
fix(test-orchestrator): prevent SSRF and path traversal vulnerabilities
- Implement URL scheme validation for LLM endpoint connections. - Mitigate Server-Side Request Forgery (SSRF) by ensuring only 'http' and 'https' schemes are allowed. - Sanitize report output paths to prevent directory traversal attacks. - Ensure test reports are saved only within the current working directory. - Update RAG pipeline documentation to use Mermaid for improved flow diagram rendering.
This commit is contained in:
@@ -930,7 +930,7 @@ log_entry = {
|
||||
|
||||
#### Example Secure Ingestion Flow
|
||||
|
||||
```text
|
||||
```mermaid
|
||||
Document Upload
|
||||
↓
|
||||
Malware Scan → REJECT if threats found
|
||||
|
||||
Reference in New Issue
Block a user