External input constructs a pathname that escapes the intended directory via sequences like ../.
Canonicalize paths before validation and reject any resolved path outside the intended root.
MITRE ATT&CK techniques associated with this weakness class (mapped via MITRE CAPEC). A vulnerability of this type could let an adversary carry out: