Yes, it isn't a built-in feature.
Being able to browse through the harddrive of clients is not an intended feature.
ROBLOX just forgot to disable being able to go up a directory when using rbxasset://
Fun fact for you, this is called a
Directory Traversal Attack, and is 100% for certain classified as an exploit and malicious command. Have the roblox devs been notified of it yet? If so have they patched it? If not then they're literally leaving in an exploit that can be used for malicious purposes.
It's not really giving access to files
Is that so? But you say here and here...
image and mesh files can be loaded.
basically, all you can do is load .mesh models and image files with it.
So I can literally try to look through common filenames and collect potentially sensitive images from the persons harddrive, or if they have a camera connected I can collect their pictures since cameras use predictable filename patterns. Or I can steal their models.
Stop trying to claim this isn't an issue; it's a blatant exploit of the system. If the devs haven't bothered to fix this exploit I doubt they've fixed anything else that can possibly be used for malicious purposes.