{"record":{"id":"d55801d64dd7969f","repo":"pypa/pip","slug":"use-of-or-absolute-path-in-a-resource-path-is-n","errorCode":null,"errorMessage":"Use of .. or absolute path in a resource path is not allowed.","messagePattern":"Use of \\.\\. or absolute path in a resource path is not allowed\\.","errorType":"validation","errorClass":"ValueError","httpStatus":null,"severity":"warning","filePath":"src/pip/_vendor/pkg_resources/__init__.py","lineNumber":1818,"sourceCode":"        >>> vrp(None)\n        Traceback (most recent call last):\n        ...\n        AttributeError: ...\n        \"\"\"\n        invalid = (\n            os.path.pardir in path.split(posixpath.sep)\n            or posixpath.isabs(path)\n            or ntpath.isabs(path)\n            or path.startswith(\"\\\\\")\n        )\n        if not invalid:\n            return\n\n        msg = \"Use of .. or absolute path in a resource path is not allowed.\"\n\n        # Aggressively disallow Windows absolute paths\n        if (path.startswith(\"\\\\\") or ntpath.isabs(path)) and not posixpath.isabs(path):\n            raise ValueError(msg)\n\n        # for compatibility, warn; in future\n        # raise ValueError(msg)\n        issue_warning(\n            msg[:-1] + \" and will raise exceptions in a future release.\",\n            DeprecationWarning,\n        )\n\n    def _get(self, path) -> bytes:\n        if hasattr(self.loader, 'get_data') and self.loader:\n            # Already checked get_data exists\n            return self.loader.get_data(path)  # type: ignore[attr-defined]\n        raise NotImplementedError(\n            \"Can't perform this operation for loaders without 'get_data()'\"\n        )\n\n\nregister_loader_type(object, NullProvider)","sourceCodeStart":1800,"sourceCodeEnd":1836,"githubUrl":"https://github.com/pypa/pip/blob/f399c3718970b1b0e2478dac5296eb62679a9b86/src/pip/_vendor/pkg_resources/__init__.py#L1800-L1836","documentation":"Raised (or warned) by NullProvider._validate_resource_path() when a resource name contains '..' (parent traversal) or is an absolute path. For Windows absolute/UNC paths it raises ValueError immediately; for POSIX '..' or absolute paths it currently issues a DeprecationWarning (the message says it 'will raise exceptions in a future release'). This is a security guard against path traversal in resource access.","triggerScenarios":"Passing a resource name like '../secret.txt', '/etc/passwd', or '\\\\server\\share' to resource_string/resource_filename/etc. The check splits on posixpath.sep and tests for os.path.pardir, posixpath.isabs, ntpath.isabs, or a leading backslash.","commonSituations":"Constructing resource paths from user input without sanitization; building a path with os.path.join that introduces '..'; cross-platform bugs where a Windows absolute path is passed on any OS.","solutions":["Sanitize resource names: reject any path containing '..' or starting with '/' or a drive letter.","Use only simple relative names (e.g. 'data/config.json') and let the provider join them under the package root.","On Windows, never pass UNC or drive-absolute paths as resource names."],"exampleFix":"// before\ndata = resource_string('mypkg', '../../../etc/passwd')  # traversal blocked\n// after\ndata = resource_string('mypkg', 'config/passwd')  # relative, inside package","handlingStrategy":"validation","validationCode":"import os, posixpath, ntpath\nINVALID = (os.path.pardir in resource_name.split(posixpath.sep)\n           or posixpath.isabs(resource_name)\n           or resource_name.startswith('\\\\\\\\'))\nif INVALID:\n    raise ValueError('resource name must be relative without ..')","typeGuard":"def is_safe_resource_name(name: str) -> bool:\n    import posixpath, ntpath, os\n    return not (os.path.pardir in name.split(posixpath.sep)\n               or posixpath.isabs(name) or ntpath.isabs(name)\n               or name.startswith('\\\\'))","tryCatchPattern":"try:\n    resource_string('pkg', name)\nexcept ValueError:\n    # path traversal attempt; reject","preventionTips":["Never build resource names from untrusted input without sanitizing.","Use only simple relative paths inside the package root."],"tags":["pkg-resources","resources","security","path-traversal","deprecation"],"backgroundTag":null,"analyzedSha":"f399c3718970b1b0e2478dac5296eb62679a9b86","analyzedAt":"2026-08-08T23:01:42.227Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}