⚠ Sandboxed environment — This is an intentionally vulnerable application running inside an isolated Docker container with fake data. Nothing you do here can harm the host machine or other users.

A01 – Broken Access Control

OWASP A01:2025 CWE-22 CWE-200 CWE-548 CWE-639

Four different ways access control can fail. Each tab below isolates one CWE so you can focus on it. All four share the same root cause: the server trusts a user-supplied value to decide what data to return.

CWE-22 Path Traversal CWE-200 IDOR CWE-548 Directory Listing CWE-639 Privilege Key
CWE-22 Path Traversal

The app reads files inside /tmp/demo/userfiles. It builds the full path with os.path.join and opens it — without checking the result stayed inside that directory.

Vulnerable code:
path = os.path.join(USER_DIR, filename)
return open(path).read()

Try it yourself

Legitimate read

Submit note1.txt. Normal behaviour.

Climb out

Submit ../fakepasswd. The .. escapes USER_DIR.