From ca40c771d0759e1ca90404846935e3b2ea988450 Mon Sep 17 00:00:00 2001 From: Parker Moore Date: Tue, 21 Oct 2014 09:00:41 -0700 Subject: [PATCH] Only allow CWD _layouts outside of safe mode. --- lib/jekyll/layout_reader.rb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/jekyll/layout_reader.rb b/lib/jekyll/layout_reader.rb index d67363fb..a8466beb 100644 --- a/lib/jekyll/layout_reader.rb +++ b/lib/jekyll/layout_reader.rb @@ -43,7 +43,7 @@ module Jekyll def layout_directory_in_cwd dir = Jekyll.sanitized_path(Dir.pwd, site.config['layouts']) - if File.directory?(dir) + if File.directory?(dir) && !site.safe dir else nil