SiteShadow
Back to vulnerability library
Detected byCWE-aware static analysis

CWE-22 Path Traversal

Coverage: 43 rules in the SiteShadow rule registry target this CWE (registry v2.0.0). Regex 36Other-pattern 7 Also: Taint and heuristic analyzers may also detect related flows (see coverage for the authoritative list) Registry tagging shows intent, for sample-level behaviour and benchmarked gaps see known gaps.

What this means

SiteShadow detected a path construction pattern where untrusted input may control what file is read or written.

Why it matters

Safer examples

1) Map IDs to known files (instead of accepting paths)

const files = {
  invoice: "/srv/reports/invoice.csv",
  summary: "/srv/reports/summary.json",
};
const path = files[req.query.type] ?? files.summary;

2) Normalize + enforce a base directory

from pathlib import Path

base = Path("/srv/uploads").resolve()
candidate = (base / filename).resolve()
if base not in candidate.parents:
    raise ValueError("Invalid path")

3) Validate file extensions only as an extra check

Extensions help but are not enough on their own. Prefer allowlists and base-dir enforcement.

How SiteShadow detects it (high level)

References

---

← Back to Vulnerability Library

Catch this in your code with SiteShadow.

Every released SiteShadow scanner is free, including full project analysis, reports, patterns, dashboard access, and configured organization SSO.