warriordeere
It is possible to read any file on the user client (NextJS Server Side) by using the API to read mission files, which is not intended. e.g.: If you run the app in dev mode (`npm run dev`) and then open `http://localhost:3000/api/mission/file?path=../../build.rs` in the browser, the content of the file is displayed even though it is not in the `/data/missions/...` directory. I'm not sure how this is potentially exploitable, but I would rather consider restricting access to the ``data/missions/...`` folder. If necessary, this can be extended to the whole data folder for other APIs, but nothing beyond that.