syncfusion-blazor-rich-text-editor
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
SecuritySecurityreferences/images-and-media.md
MEDIUMSecurityMEDIUM
references/images-and-media.md
The fragment is documentation with legitimate rich-text media functionality and no apparent malware. However, the upload controller contains a significant server-side path traversal/arbitrary file-write risk because it uses an unsanitized client filename, and it lacks server-side type and size validation. External media URLs and the unspecified delete endpoint also require strict validation. The sample should not be used in production without canonical path enforcement, filename generation or basename sanitization, allowlisted content validation, size limits, and safe deletion logic.
Confidence: 98%Severity: 78%
Audit Metadata