{"version":"2.1.281","anchor":"upload-asset-refuses-network-paths-and-unvettable-link-chain","canonical_anchor":"upload-asset-refuses-network-paths-and-unvettable-link-chain","heading":"upload_asset refuses network paths and unvettable link chains","tier":"notice","area":"Chrome","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281\/e\/upload-asset-refuses-network-paths-and-unvettable-link-chain","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281","markdown":"### upload_asset refuses network paths and unvettable link chains\n\n`upload_asset` now refuses network paths, device paths and symlinks it cannot fully check\n\n**Unclear.** The finding does not say how `upload_asset` is reached or whether the 256 depth constant is the symlink limit.\n\n**What**\n\n`upload_asset` now refuses a file path when it:\n\n- Is a Windows network share (UNC path)\n\n- Is under a `\/net` automount\n\n- Is a device-style path\n\n- Reaches one of these through a symlink, which is a file that points to another location\n\n- Has a part that could not be examined\n\nA separate `ELOOP` error covers chains of symlinks too long to check. The refusal message says `upload_asset` reads only local files.\n\n**Why**\n\nOnly files actually on your machine can be uploaded, so a path cannot quietly send something from a network location.\n\n- Area: Chrome\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5"}