~ / cases / arbitrary-file-read
◉ Arbitrary File Read
LFI, path traversal, SSRF chains — reading files and secrets the app never meant to expose.
[docker lab] file-boundary
Test path traversal and learn how filesystem boundaries fail. Run it locally to practice the proof of concept in an isolated environment.
docker compose -f labs/arbitrary-file-read up --buildaurora@hack:~$ ls ./cases/arbitrary-file-read
Trusted Chat to ZIP Upload with Symbolic Links
A trusted chat workflow let an AI scanner download and extract a ZIP containing symbolic links, turning a legitimate-looking coverage report into an arbitrary file read.
Trusted Chat to Pickle Deserialization via bashExecutor
A chat agent blocked direct .pkl uploads but accepted a ZIP containing a legitimate CSV and a hidden pickle payload, which was later loaded through an exposed execution tool.
other classes: rce · prompt-injection-role-confusion · sqli · system-prompt-exfiltration