SiteShadow
Back to vulnerability library
Detected byCWE-aware static analysis

CWE-313 Cleartext Storage in a File or on Disk

Coverage: 6 rules in the SiteShadow rule registry target this CWE (registry v2.0.0). Regex 6 Also: Taint and heuristic analyzers may also detect related flows (see coverage for the authoritative list) Registry tagging shows intent, for sample-level behaviour and benchmarked gaps see known gaps.

What this means

SiteShadow flagged sensitive information being written to files on disk in plaintext (logs, exports, caches, temp files, backups).

Why it matters

Cleartext files are easy to copy and exfiltrate.

Safer examples

1) Don't write secrets to disk

Keep secrets in a secret manager and inject at runtime; avoid dumping configs with secrets.

2) Use strict permissions and protected locations

Write to application-owned directories and set restrictive permissions.

3) Encrypt sensitive exports

If you must export sensitive data, encrypt the output and control key distribution.

How SiteShadow detects it (high level)

References

---

← Back to Vulnerability Library

Catch this in your code with SiteShadow.

Every released SiteShadow scanner is free, including full project analysis, reports, patterns, dashboard access, and configured organization SSO.