Skip to content

Conversation

@EsadCetiner
Copy link
Member

Blocking the .url file extension causes false positives in the Nextcloud Bookmarks app when adjusting settings in the admin panel because of this URL path: /apps/bookmarks/admin/settings/previews.generic.url.

I can't think of any viable attack scenario that involves this file for an web application, this file type is primarily for linking to websites or email addresses on a desktop computer.

https://fileinfo.com/extension/url

@github-actions
Copy link
Contributor

github-actions bot commented Sep 5, 2025

📊 Quantitative test results for language: eng, year: 2023, size: 10K, paranoia level: 1:
🚀 Quantitative testing did not detect new false positives

Copy link
Contributor

@franbuehler franbuehler left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

@EsadCetiner EsadCetiner added this pull request to the merge queue Sep 5, 2025
Merged via the queue into coreruleset:main with commit cd15f8a Sep 5, 2025
7 checks passed
@EsadCetiner EsadCetiner deleted the fix-dont-block-url-extension branch September 5, 2025 19:58
@fzipi fzipi mentioned this pull request Oct 2, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants