Both handlers concatenated the request path onto the workspace root without validating containment, letting `path: "../../../etc/passwd"` escape the workspace. resolveUnderRoot normalizes the path and checks containment under root.absolute.path before any filesystem access. Co-Authored-By: Claude <noreply@anthropic.com>