Skip to content

Add a plugin to detect os.join with input #477

@ericwb

Description

@ericwb

Transfer of OpenStack blueprint to GH issue:
https://blueprints.launchpad.net/bandit/+spec/add-os-join-plugin

If os.join is used with un-filtered user input it can lead to path traversal. A plugin that detects its use could be useful for pentesting.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions