A simple sudoers rule should not allow the user to set the cwd: Parses OK Entries for user root: ALL = /bin/ls host allowed runas allowed cmnd allowed User root is not allowed to change directory to / Password required Command denied User cannot override the sudoers cwd: Parses OK Entries for user root: ALL = CWD=/some/where/else /bin/ls host allowed runas allowed cmnd allowed User root is not allowed to change directory to / Password required Command denied User can set cwd if sudoers rule sets cwd to '*': Parses OK Entries for user root: ALL = CWD=* /bin/ls host allowed runas allowed cmnd allowed Password required Command allowed User can set cwd runcwd Defaults is '*': Parses OK Entries for user root: ALL = /bin/ls host allowed runas allowed cmnd allowed Password required Command allowed