Skip to content

Detects variable in filename argument of "fs" calls, which might allow an attacker to access anything on your system (security/detect-non-literal-fs-filename)

⚠️ This rule warns in the ✅ recommended config.

More information: OWASP Path Traversal

Released under the Apache License 2.0.