# Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory. **Stack:** Python - Prevalence: Alta Frecuentemente explotada - Impact: Crítico 1 reglas de severidad crítica - Prevention: Documentada 6 ejemplos de corrección **OWASP:** Broken Access Control (A01:2021-Broken Access Control) - #1 ## Description Many file operations are intended to take place within a restricted directory. By using special elements such as '..' and '/' separators, attackers can escape outside of the restricted location to access files or directories that are elsewhere on the system. ## Prevention Estrategias de prevención para Path Traversal basadas en 2 reglas de detección de Shoulder. ### Python Use os.path.basename() or pathlib to restrict file access to intended directories Validate extracted file paths stay within the target directory before writing ## Warning Signs - [HIGH] untrusted user input being used in file system operations without proper validation - [HIGH] unsafe extraction of ZIP/TAR archives without path validation ## Consequences - Leer archivos o directorios - Modificar archivos o directorios - Ejecutar código no autorizado ## Mitigations - Usa una biblioteca o framework verificado que no permita que ocurra esta debilidad - Usa una lista de permitidos de entradas aceptables que cumplan estrictamente con las especificaciones - Para nombres de archivo, usa listas de permitidos estrictas que limiten el conjunto de caracteres ## Detection - Total rules: 6 - Critical: 1 - Languages: go, javascript, typescript, python ## Rules by Language ### Python (2 rules) - **Path Traversal / Directory Traversal** [HIGH]: Detects untrusted user input being used in file system operations without proper validation. - Remediation: Use os.path.basename() to extract the filename only. ```python import os safe_filename = os.path.basename(user_filename) ``` Learn more: https://shoulder.dev/learn/python/cwe-22/path-traversal - **Zip Slip / Archive Path Traversal** [HIGH]: Detects unsafe extraction of ZIP/TAR archives without path validation. Malicious archives can contain filenames with "../" to write files outside the intended directory (path traversal). Always validate extracted paths. - Remediation: Validate that extracted paths stay within the target directory before writing. ```python import zipfile import os def safe_extract(zip_path, extract_to): with zipfile.ZipFile(zip_path, 'r') as zf: for member in zf.namelist(): target = os.path.normpath(os.path.join(extract_to, member)) if not target.startswith(os.path.abspath(extract_to)): raise ValueError(f"Path traversal: {member}") zf.extract(member, extract_to) ``` Learn more: https://shoulder.dev/learn/python/cwe-22/zip-slip