⚠ Sandboxed environment — This is an intentionally vulnerable application running inside an isolated Docker container with fake data. Nothing you do here can harm the host machine or other users.

A01 – Broken Access Control

OWASP A01:2025 CWE-22 CWE-200 CWE-548 CWE-639

Four different ways access control can fail. Each tab below isolates one CWE so you can focus on it. All four share the same root cause: the server trusts a user-supplied value to decide what data to return.

CWE-22 Path Traversal CWE-200 IDOR CWE-548 Directory Listing CWE-639 Privilege Key
CWE-548 Information Exposure Through Directory Listing

A "browse files" feature lists everything in a directory. Filenames alone leak backups, dotfiles, source code. Worse: the directory comes from the URL, so attackers peek wherever they like.

Vulnerable code:
d = request.args.get('dir') or USER_DIR
return '\n'.join(os.listdir(d))   # no path check

Try it yourself

The intended directory

List /tmp/demo/userfiles — public notes.

Peek where you shouldn't

Change dir to /tmp/demo or /etc.