Guest programs can access the host filesystem by default. Relative paths are resolved from the process working directory.
For example, JavaScript can use node:fs:
const { readFileSync, writeFileSync } = require("node:fs");
const text = readFileSync("hello.txt", "utf8");
writeFileSync("out.txt", text.toUpperCase());This page describes access policy, not the functions implemented by node:fs.
See the Node Filesystem API for that surface.
Restrict access
Sandbox flags switch filesystem access to deny-by-default. Grant only the paths the program needs:
elide --allow-read=. --allow-write=./out run app.js--allow-read and --allow-write imply --sandbox. The bare form grants all
paths; attach =PATH[,PATH] to scope a grant. Use --fs-audit to print access
decisions to stderr.
Continue with Filesystem Sandbox for subprocess and network grants.