security fix: replaced sprintf with snprintf