Skip to content

Conversation

@Adityav369
Copy link
Collaborator

… across SDK methods. Update parameters to include folder_name and folder_depth for scoping in various document and graph operations.

… across SDK methods. Update parameters to include folder_name and folder_depth for scoping in various document and graph operations.
@jazzberry-ai
Copy link

jazzberry-ai bot commented Dec 6, 2025

Bug Report

Name Severity Example test case Description
Folder Depth Bypass High Call retrieve_chunks with folder_name="/" and folder_depth=-1 If the server-side code does not properly validate the folder_depth parameter, a malicious user could potentially bypass folder scoping and access documents in folders they are not authorized to access.

Comments? Email us.

@Adityav369 Adityav369 merged commit 421d414 into main Dec 6, 2025
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants