Jekyll Arbitrary File Write

Because Jekyll was sanitizing file paths prior to URL decoding the path, it was possible to set a permalink to write a generated page outside of the output directory. This is not an issue for most users of Jekyll. It is if you are GitHub and build users' sites for

