Path traversal ruleset

clearplane-path-traversal detects traversal sequences and sensitive path patterns. Level-2 supplements inspect traversal revealed by repeated URL decoding.

Paranoia levels and compatibility

File managers and developer tools may legitimately accept relative paths, dotfiles and source examples. The ruleset also flags same-origin redirect destinations containing encoded parent segments at level 2. Review level-1 findings and the additional level-2 decoding checks on those routes. A path match describes suspicious input; upstream path normalization and filesystem access controls remain application responsibilities.

Start in Detection, review detections, and configure only the exclusions needed for the affected route and field.

See the measured coverage for the exact tested payload hashes, missed detections and false-positive rates. Ruleset operation explains activation, stages and rollback.