Sandbox media handling had a time-of-check/time-of-use gap: media paths could be validated first and read later through a separate path. A symlink retarget between those steps could cause reads outside sandboxRoot.
Affected versions could permit host file reads outside the intended sandbox root in media attachment/image flows.
Media reads now use consolidated root-scoped, boundary-safe read paths at use time, removing check/use drift across call sites.
<= 2026.2.262026.3.1{
"cwe_ids": [
"CWE-367",
"CWE-59"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-02T21:55:47Z",
"nvd_published_at": null,
"severity": "HIGH"
}