neurolink
neurolink copied to clipboard
IMG-020: Weak Data URI Validation
Summary
Data URI validation only checks for 'data:' prefix and 'base64,' delimiter.
Root Cause
Lines 420-426 minimal validation without MIME type or base64 content validation.
Fix
Use strict regex and validate base64 content.
Acceptance Criteria
- [ ] Implement strict data URI regex validation
- [ ] Validate MIME type format (type/subtype)
- [ ] Validate base64 content
- [ ] Add tests for valid and invalid data URIs