The Path That Climbed Out — Python Bug Hunt
Inspired by the vulnerability class that never dies — from web servers in the 90s to container escapes today: a filename with ../ in it walks straight out…
- Language: Python
- Layer: Backend
- Difficulty: Medium
- Concepts: Security, Path Traversal
- Modelled on: Path traversal · CWE-22
- Visible tests: ordinary paths join under the base; dot-dot segments are rejected; absolute paths are rejected
- Reward: 50 XP for a complete fix
Briefing
Inspired by the vulnerability class that never dies — from web servers in the 90s to container escapes today: a filename with ../ in it walks straight out of the sandbox and reads /etc/passwd.
filestore.py joins user-supplied paths onto a base directory. It must refuse to climb.
Bug report
BUG-DOTDOT · Priority: Critical · Reported by: bug bounty
safe_join(base, user_path):
- reject absolute paths and any ".." segment -> raise ValueError
- otherwise return base + "/" + normalized path ("." segments dropped)
Observed: GET /files/..%2F..%2Fetc%2Fpasswd returns the real thing.
Logs
[files] serving "uploads/../../etc/passwd"The code as shipped
src/fs/filestore.py (editable)
# Joins a user-supplied path onto the storage root.
def safe_join(base, user_path):
return base + "/" + user_path
Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More Python bug hunts.