FBI and CISA tell developers to address security issues before releasing them

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) issued a new joint security alert earlier this week, urging software developers to consider path traversal when developing software products.

Path traversal is a software vulnerability also called directory traversal or directory climbing. Exploiting this flaw can allow threat actors to gain access to sensitive files and folders. The hole usually arises in web applications or systems that dynamically construct file paths based on user input without properly validating or sanitizing them.