mirror of
https://github.com/blender/blender
synced 2026-09-29 04:37:17 +03:00
The use of wordexp(3) permits arbitrary code execution from manually-crafted
glTF files. See https://github.com/syoyo/tinygltf/issues/368 for more details.
In practice this shouldn't be an issue for Blender since the GlTF data isn't
manually crafted but from the OpenXR runtime (a bit like a driver). But
updating the library to include the fix is not a big deal anyway.
Note that the warning that required the local modification is no longer present upstream since
|
||
|---|---|---|
| .. | ||
| README.blender | ||
| tiny_gltf.h | ||
Project: TinyGLTF URL: https://github.com/syoyo/tinygltf License: MIT Upstream version: 2.8.3, 84a83d39f55d Local modifications: None