pypa/pip · warning · ValueError

Use of .. or absolute path in a resource path is not…

Error message

Use of .. or absolute path in a resource path is not allowed.

What it means

Raised (or warned) by NullProvider._validate_resource_path() when a resource name contains '..' (parent traversal) or is an absolute path. For Windows absolute/UNC paths it raises ValueError immediately; for POSIX '..' or absolute paths it currently issues a DeprecationWarning (the message says it 'will raise exceptions in a future release'). This is a security guard against path traversal in resource access.

Solutions

  1. Sanitize resource names: reject any path containing '..' or starting with '/' or a drive letter.
  2. Use only simple relative names (e.g. 'data/config.json') and let the provider join them under the package root.
  3. On Windows, never pass UNC or drive-absolute paths as resource names.

Example fix

// before
data = resource_string('mypkg', '../../../etc/passwd')  # traversal blocked
// after
data = resource_string('mypkg', 'config/passwd')  # relative, inside package
Defensive patterns

Strategy: validation

Validate before calling

import os, posixpath, ntpath
INVALID = (os.path.pardir in resource_name.split(posixpath.sep)
           or posixpath.isabs(resource_name)
           or resource_name.startswith('\\\\'))
if INVALID:
    raise ValueError('resource name must be relative without ..')

Type guard

def is_safe_resource_name(name: str) -> bool:
    import posixpath, ntpath, os
    return not (os.path.pardir in name.split(posixpath.sep)
               or posixpath.isabs(name) or ntpath.isabs(name)
               or name.startswith('\\'))

Try / catch

try:
    resource_string('pkg', name)
except ValueError:
    # path traversal attempt; reject

Prevention

When it happens

Trigger: Passing a resource name like '../secret.txt', '/etc/passwd', or '\\server\share' to resource_string/resource_filename/etc. The check splits on posixpath.sep and tests for os.path.pardir, posixpath.isabs, ntpath.isabs, or a leading backslash.

Common situations: Constructing resource paths from user input without sanitization; building a path with os.path.join that introduces '..'; cross-platform bugs where a Windows absolute path is passed on any OS.

Related errors


AI-assisted analysis of pypa/pip@f399c37189 (2026-08-08). Data as JSON: /api/errors/d55801d64dd7969f. Report an issue: GitHub.

Appendix: source

Thrown at src/pip/_vendor/pkg_resources/__init__.py:1818

        >>> vrp(None)
        Traceback (most recent call last):
        ...
        AttributeError: ...
        """
        invalid = (
            os.path.pardir in path.split(posixpath.sep)
            or posixpath.isabs(path)
            or ntpath.isabs(path)
            or path.startswith("\\")
        )
        if not invalid:
            return

        msg = "Use of .. or absolute path in a resource path is not allowed."

        # Aggressively disallow Windows absolute paths
        if (path.startswith("\\") or ntpath.isabs(path)) and not posixpath.isabs(path):
            raise ValueError(msg)

        # for compatibility, warn; in future
        # raise ValueError(msg)
        issue_warning(
            msg[:-1] + " and will raise exceptions in a future release.",
            DeprecationWarning,
        )

    def _get(self, path) -> bytes:
        if hasattr(self.loader, 'get_data') and self.loader:
            # Already checked get_data exists
            return self.loader.get_data(path)  # type: ignore[attr-defined]
        raise NotImplementedError(
            "Can't perform this operation for loaders without 'get_data()'"
        )


register_loader_type(object, NullProvider)

View on GitHub (pinned to f399c37189)