On 05/26/2013 01:20 AM, Dylan Baker wrote: > From my reading of the current summary code it doesn't handle cases of > malicious tests using shell expansion. Well, that's sort of what testPathToHtmlFilename does...it removes any characters other than [a-zA-z0-9_].