TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Doyensec

CSPT Resources

2025-03-26 · Read original ↗

ATT&CK techniques detected

2 predictions
T1190Exploit Public-Facing Application
91%
"cspt resources as a follow up to maxence schmitt ’ s research on client - side path traversal ( cspt ), we wanted to encourage researchers, bug hunters, and security professionals to explore cspt further, as it remains an underrated yet impactful attack vector. to support the com…"
T1588.006Vulnerabilities
31%
"##p lisbon 2024 - exploiting client - side path traversal : csrf is dead, long live csrf maxence schmitt : volcamp 2024 - fr : exploiting client - side path traversal : csrf is dead, long live csrf soheil khodayari : owasp lisbon 2024 - deep dive into cspt techniques justin gardn…"

Summary

New CSPT toys for everyone

As a follow up to Maxence Schmitt’s research on Client-Side Path Traversal (CSPT), we wanted to encourage researchers, bug hunters, and security professionals to explore CSPT further, as it remains an underrated yet impactful attack vector.

To support the community, we have compiled a list of blog posts, vulnerabilities, tools, CTF challenges, and videos related to CSPT. If anything is missing, let us know and we will update the post. Please note that the list is not ranked and does not reflect the quality or importance of the resources.

Publications (blog posts, advisories, …)

Videos

Tools

Challenges

Labs

Thank you and good luck!

We hope this collection of resources will help the community to better understand and explore Client-Side Path Traversal (CSPT) vulnerabilities. We encourage anyone interested to take a deep dive into exploring CSPT techniques and possibilities and helping us to push the boundaries of web security. We wish you many exciting discoveries and plenty of CSPT-related bugs along the way!

More Information

This research project was made with ♡ by Maxence Schmitt, thanks to the 25% research time Doyensec gives its engineers. If you would like to learn more about our work, check out our blog, follow us on X, Mastodon, BlueSky or feel free to contact us at [email protected] for more information on how we can help your organization “Build with Security”.