Client-Side Path Traversal: When Apps Forge Requests for You
Client-Side Path Traversal can trick an app’s own frontend into sending one somewhere it was never meant to go. The user’s authentication comes along, even while modern CSRF defenses keep working as designed. What looks like a minor path-handling bug can become account takeover, XSS, or token theft.








