What it is: Unquoted Search Path or Element (CWE-428) is a vulnerability where an unquoted element in a search path can be manipulated to access parent directory resources.
Why it matters: This issue allows attackers to execute unauthorized code, compromising system security and integrity.
How to fix it: Properly quote the full search path before execution.
TL;DR: Unquoted Search Path or Element (CWE-428) is a vulnerability where unquoted elements in search paths can be manipulated, leading to unauthorized access and code execution. To prevent this, ensure all search paths are properly quoted.
| Field | Value |
|---|---|
| CWE ID | CWE-428 |
| OWASP Category | Not directly mapped |
| CAPEC | None known |
| Typical Severity | Critical |
| Affected Technologies | any system that uses search paths or environment variables |
| Detection Difficulty | Moderate |
| Last Updated | 2026-07-29 |
What is Unquoted Search Path or Element?
Unquoted Search Path or Element (CWE-428) is a type of vulnerability where an unquoted element in a search path can be manipulated to access parent directory resources. As defined by the MITRE Corporation under CWE-428, and classified by the OWASP Foundation as not directly mapped.
Quick Summary
Unquoted Search Path or Element (CWE-428) is a serious security vulnerability that allows attackers to manipulate unquoted elements in search paths to access parent directory resources. This can lead to unauthorized code execution and compromise system integrity. Understanding and mitigating this issue is crucial for maintaining secure systems.
Jump to: Quick Summary · Unquoted Search Path or Element Overview · How Unquoted Search Path or Element Works · Business Impact of Unquoted Search Path or Element · Unquoted Search Path or Element Attack Scenario · How to Detect Unquoted Search Path or Element · How to Fix Unquoted Search Path or Element · Framework-Specific Fixes for Unquoted Search Path or Element · How to Ask AI to Check Your Code for Unquoted Search Path or Element · Unquoted Search Path or Element Best Practices Checklist · Unquoted Search Path or Element FAQ · Vulnerabilities Related to Unquoted Search Path or Element · References · Scan Your Own Site
Unquoted Search Path or Element Overview
What
Unquoted Search Path or Element (CWE-428) is a vulnerability where unquoted elements in search paths can be manipulated to access parent directory resources.
Why it matters
This issue allows attackers to execute unauthorized code, compromising system security and integrity. It affects any system that uses search paths or environment variables containing whitespace or other separators.
Where it occurs
Unquoted Search Path or Element vulnerabilities occur when a program constructs a path from user input without proper quoting.
Who is affected
Applications that process untrusted inputs to construct file paths are at risk.
Who is NOT affected
Systems already using properly quoted search paths and environment variables are not vulnerable.
How Unquoted Search Path or Element Works
Root Cause
The root cause of this vulnerability lies in the improper handling of whitespace characters in search path elements, which can be manipulated to access parent directory resources.
Attack Flow
- An attacker identifies an unquoted element in a search path.
- The attacker manipulates the input to include parent directory references (e.g.,
..\). - The system executes commands or processes using the altered search path.
Prerequisites to Exploit
- Unquoted elements in search paths containing whitespace or other separators.
- Ability to manipulate inputs that construct these paths.
Vulnerable Code
import os
path = input("Enter a file path: ")
os.chdir(path)
This code accepts user input and changes the current directory without proper validation, allowing an attacker to inject parent directory references.
Secure Code
import os
base_dir = '/safe/path'
path = input("Enter a file path: ")
if not os.path.abspath(path).startswith(base_dir):
raise ValueError('Invalid path')
os.chdir(os.path.abspath(path))
This secure code ensures that the provided path starts with a safe base directory before changing to it, preventing unauthorized access.
Business Impact of Unquoted Search Path or Element
Confidentiality
Unquoted search paths can lead to exposure of sensitive data stored in parent directories.
Integrity
Attackers may modify files or execute commands in parent directories, compromising system integrity.
Availability
System availability can be disrupted if critical processes are compromised through unquoted search paths.
Unquoted Search Path or Element Attack Scenario
- An attacker identifies an application accepting file path inputs.
- The attacker manipulates the input to include
..\references. - The application changes directory using the manipulated path, leading to unauthorized access and code execution.
How to Detect Unquoted Search Path or Element
Manual Testing
- Review all code paths that construct search paths from user input.
- Ensure proper quoting of elements containing whitespace or separators.
- Verify that inputs are validated against a safe base directory before use.
Automated Scanners (SAST / DAST)
Static analysis can identify unquoted elements in search paths, while dynamic testing can confirm the vulnerability’s impact during runtime.
PenScan Detection
PenScan uses ZAP and Nuclei to detect unquoted elements in environment variables and system configurations.
False Positive Guidance
False positives may occur if the path is properly validated against a safe base directory before use.
How to Fix Unquoted Search Path or Element
- Properly quote the full search path before executing any commands.
- Validate inputs against a known safe base directory.
Framework-Specific Fixes for Unquoted Search Path or Element
Python/Django
base_dir = '/safe/path'
path = input("Enter a file path: ")
if not os.path.abspath(path).startswith(base_dir):
raise ValueError('Invalid path')
os.chdir(os.path.abspath(path))
How to Ask AI to Check Your Code for Unquoted Search Path or Element
Review the following Python code block for potential CWE-428 Unquoted Search Path or Element vulnerabilities and rewrite it using proper quoting: [paste code here]
Unquoted Search Path or Element Best Practices Checklist
- ✅ Properly quote all elements in search paths containing whitespace.
- ✅ Validate inputs against a known safe base directory before use.
Unquoted Search Path or Element FAQ
How does an unquoted search path vulnerability work?
An attacker can manipulate the search path to access resources in a parent directory, leading to unauthorized code execution or command injection.
Can you provide real-world examples of unquoted search paths causing issues?
Real-world cases include misconfigured environment variables that allow attackers to inject malicious commands into system processes.
What is the impact of an unquoted search path vulnerability on a system?
It can lead to unauthorized access and execution of code, compromising confidentiality, integrity, and availability of data.
How do you detect unquoted search paths in your application?
Use static analysis tools like ZAP or Nuclei to scan for unquoted elements in environment variables or system configurations.
What are the best practices to prevent unquoted search path vulnerabilities?
quote: Ensure all search paths and environment variables are properly quoted, especially those containing whitespace.
How can you fix an existing unquoted search path vulnerability?
Properly quote the entire search path before executing any commands or processes that rely on it.
What is the relationship between CWE-428 and other security weaknesses?
CWE-428 is a specific variant of CWE-668, which involves exposure of resources to an incorrect scope.
Vulnerabilities Related to Unquoted Search Path or Element
| CWE | Name | Relationship |
|---|---|---|
| CWE-668 | Exposure of Resource to Wrong Sphere | ChildOf |
References
Scan Your Own Site
Manual code review catches what you know to look for. An automated scan catches what you didn’t. Scan your own website using PenScan to find Unquoted Search Path or Element and other risks before an attacker does.