The Path That Climbed Out — Python Bug Hunt

Inspired by the vulnerability class that never dies — from web servers in the 90s to container escapes today: a filename with ../ in it walks straight out…

  • Language: Python
  • Layer: Backend
  • Difficulty: Medium
  • Concepts: Security, Path Traversal
  • Modelled on: Path traversal · CWE-22
  • Visible tests: ordinary paths join under the base; dot-dot segments are rejected; absolute paths are rejected
  • Reward: 50 XP for a complete fix

Briefing

Inspired by the vulnerability class that never dies — from web servers in the 90s to container escapes today: a filename with ../ in it walks straight out of the sandbox and reads /etc/passwd.

filestore.py joins user-supplied paths onto a base directory. It must refuse to climb.

Bug report

BUG-DOTDOT · Priority: Critical · Reported by: bug bounty

safe_join(base, user_path):

  • reject absolute paths and any ".." segment -> raise ValueError
  • otherwise return base + "/" + normalized path ("." segments dropped)

Observed: GET /files/..%2F..%2Fetc%2Fpasswd returns the real thing.

Logs

[files] serving "uploads/../../etc/passwd"

The code as shipped

src/fs/filestore.py (editable)

# Joins a user-supplied path onto the storage root.

def safe_join(base, user_path):
    return base + "/" + user_path

Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More Python bug hunts.