Mastodon Mastodon Mastodon Mastodon

Directory Traversal

Updated: · CyberSecureFox Editorial Team

Directory traversal (path traversal) is a vulnerability that lets an attacker read or write files outside the folder an application intended to expose, by manipulating file paths with sequences like ../.

How directory traversal works

Applications often build file paths from user input: download?file=report.pdf becomes /var/www/files/report.pdf. If the input is not validated, an attacker can request ../../../../etc/passwd or ..\..\windows\win.ini and climb out of the intended directory. Encoded variants (%2e%2e%2f), absolute paths and archive files with crafted names (“Zip Slip”) bypass naive filters. The weakness is catalogued as CWE-22.

Why it matters

Reading arbitrary files exposes configuration files, source code, private keys, password hashes and session data. Writing files is even worse: an attacker can drop a web shell or overwrite configuration and achieve remote code execution. Notable examples:

  • Fortinet FortiOS SSL VPN (CVE-2018-13379) – a path traversal flaw leaked VPN session files with plaintext credentials; lists of tens of thousands of affected devices were later published on hacker forums.
  • Citrix ADC/NetScaler (CVE-2019-19781) – directory traversal led to code execution and mass exploitation in early 2020.

Path traversal regularly appears in CISA’s Known Exploited Vulnerabilities catalog, especially in VPN gateways, file-transfer servers and web management interfaces, where public exploits follow disclosure quickly.

How to prevent directory traversal

  • Do not use user input directly in file paths; map requests to IDs or an allowlist of file names.
  • Canonicalise the path and verify that it stays inside the permitted base directory.
  • Run services with minimal file system permissions and isolate them (containers, chroot).
  • Validate archive entries before extracting them.

Directory traversal is closely related to other input-handling vulnerabilities such as code injection.

Synonyms:
path traversal, dot-dot-slash attack