Web Security / Injection
Lesson 11 of 27
Path traversal
If a site opens files based on a name from the URL, ../ can climb out of the intended folder. Use safe helpers and allow-lists of filenames.
Key points
- Never join user input straight into file paths
- Flask's send_from_directory checks paths
- Allow-list known files
Quiz · +10 XP
What does path traversal abuse?
Log in to save progress and earn XP.