A bug identified in this issue allows a partial filesystem scope bypass if glob characters are used within file dialog or drag-and-drop functionalities.
This PR fixes the issue by escaping glob characters.
{ "license": "CC0-1.0" }
{ "affected_functions": null, "affects": { "arch": [], "functions": [], "os": [] } }
[ "privilege-escalation" ]
null
"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:N/A:N"
"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2022-0091.json"