원클릭으로
path-traversal
Detect path traversal and Zip Slip vulnerabilities where user-controlled path components can escape intended directories.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
메뉴
Detect path traversal and Zip Slip vulnerabilities where user-controlled path components can escape intended directories.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
SOC 직업 분류 기준
Generate polished, human-sounding vulnerability disclosure reports for GHSA, HackerOne, and email. Auto-selects channel, calculates CVSS, and adapts tone.
Mine GitHub Security Advisories and CVE databases for incomplete fixes, finding variant vulnerabilities in patched code or similar patterns in related packages.
Detect authentication and authorization bypass vulnerabilities including missing auth middleware, JWT algorithm confusion, IDOR, and session fixation.
Detect code injection vulnerabilities in packages that dynamically generate or evaluate code via new Function(), eval(), vm.run*, or template literal interpolation.
Detect OS command injection via shell execution sinks where user-controlled input reaches system commands without proper sanitization.
Cross-pollination multiplier technique: find a vulnerability in one package, then search for the same pattern across all similar packages to multiply findings.
| name | path-traversal |
| description | Detect path traversal and Zip Slip vulnerabilities where user-controlled path components can escape intended directories. |
| metadata | {"filePattern":["**/*.js","**/*.ts","**/*.py","**/*.go"],"bashPattern":["semgrep.*path","grep.*(path\\.join|writeFile|extractall)"],"priority":90} |
Audit archive extraction libraries, file upload handlers, static file servers, file path utilities, and any package that writes files based on user-controlled names.
~85% CVE acceptance rate when confirmed.
path.join() does NOT prevent .. traversal in Node.js:
path.join('/uploads', '../../../etc/passwd')
// Returns: '/etc/passwd' -- NOT '/uploads/etc/passwd'
path.resolve() returns an absolute path but also does NOT validate that it stays within a base directory.
User controls a filename/path parameter that is concatenated with a base directory:
const filePath = path.join(uploadDir, req.params.filename);
fs.readFileSync(filePath); // ../../../etc/passwd
Malicious archive entries contain ../ in their filenames. During extraction, files are written outside the intended directory:
malicious.zip contains:
../../../../tmp/pwned.txt
Archive contains a symlink pointing outside the target directory, then a file targeting that symlink. During extraction, the file follows the symlink and writes to an arbitrary location.
On Windows or with naive path checks, ..\ bypasses ../ filtering:
filename = "..\\..\\..\\etc\\passwd"
%2e%2e%2f = ../
%2e%2e/ = ../
..%2f = ../
Double encoding: %252e%252e%252f
../../etc/passwd%00.png
Older systems truncate at null byte. Rare in modern runtimes.
# JavaScript/TypeScript
grep -rn "fs\.writeFile\|fs\.createWriteStream\|fs\.rename\|fs\.copyFile" .
grep -rn "fs\.readFile\|fs\.readFileSync\|fs\.createReadStream" .
grep -rn "path\.join\|path\.resolve" .
# Python
grep -rn "open(.*w\|shutil\.copy\|shutil\.move\|os\.rename" .
grep -rn "extractall\|extract(" .
# Go
grep -rn "os\.Create\|os\.OpenFile\|io\.Copy\|filepath\.Join" .
grep -rn "archive/zip\|archive/tar" .
grep -rn "unzip\|extract\|decompress\|gunzip\|untar" .
grep -rn "adm-zip\|yauzl\|unzipper\|archiver\|tar\|fflate\|JSZip\|node-7z" .
grep -rn "zipfile\|tarfile\|py7zr\|patool" .
grep -rn "startsWith\|indexOf\|includes\|realpath\|normalize" .
grep -rn "\.\." . --include="*.js" | grep -i "reject\|deny\|block\|filter"
Common INCORRECT validations:
path.join(base, input) -- does NOT prevent traversalinput.indexOf('..') === -1 -- can be bypassed with ....// or encodinginput.replace('../', '') -- bypassed with ....// (after removal, ../ remains)CORRECT validations:
path.resolve(base, input) then result.startsWith(base + path.sep) -- verifies result is within basefs.realpathSync() to resolve symlinks before checking