VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 131 of 520
  • CVE-2026-9166HigSep 10, 2026
    risk 0.49cvss 7.5epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GIS Informatics GisLab Laboratory Management System allows Path Traversal. This issue affects GisLab Laboratory Management System: from 1.4.03 before 1.5.

  • CVE-2026-15019HigSep 10, 2026
    risk 0.49cvss 7.5epss 0.01

    The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.19 via the (top-level include) function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the…

  • CVE-2026-86775HigSep 9, 2026
    risk 0.49cvss 8.6epss 0.00

    knowns (npm package) versions <= 0.29.1 contain a path traversal vulnerability in the Document API. The HTTP handler in internal/server/routes/docs.go normalizes the user-supplied document path with cleanDocPath(), which strips leading/trailing slashes and the .md suffix but…

  • CVE-2026-77110HigSep 8, 2026
    risk 0.49cvss 7.6epss 0.01

    Adobe Commerce is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to access unauthorized files or…

  • CVE-2026-77104HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.00

    CommServe contained a path traversal issue affecting information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.

  • CVE-2026-6377HigSep 7, 2026
    risk 0.49cvss 7.5epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Path Traversal. This issue affects CSM (Customer Service Management): from 6.8.9 before 8.0.3.

  • CVE-2026-50553HigSep 4, 2026
    risk 0.49cvss —epss 0.00

    Note Mark is an open-source note-taking application. Prior to version 0.19.5, Note Mark validates book and note slug values with the OpenAPI/huma tag pattern:"[a-z0-9-]+". huma compiles this with regexp.MustCompile(s.Pattern) and tests it with patternRe.MatchString(str), an…

  • CVE-2026-85606HigSep 4, 2026
    risk 0.49cvss 7.5epss 0.01

    firecrawl-mcp-server 3.20.2 contains an arbitrary local file read vulnerability in the firecrawl_parse tool that accepts unconstrained filePath arguments without directory containment validation. Attackers can supply absolute paths or directory traversal sequences to read…

  • CVE-2026-18672HigSep 2, 2026
    risk 0.49cvss 7.5epss 0.00

    In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient validation of client-supplied state in RadImageEditor may allow an attacker to influence which file is returned by the control's image cache, potentially exposing file contents outside the intended image…

  • CVE-2026-19952HigSep 1, 2026
    risk 0.49cvss 7.5epss 0.01

    The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the move_folders function in all versions up to, and including, 3.29.12. This makes it possible for unauthenticated attackers to delete…

  • CVE-2026-79407HigAug 31, 2026
    risk 0.49cvss 7.5epss 0.00

    A path traversal vulnerability in the SPO extension of MetaGPT 0.8.1 allows an attacker to read arbitrary files via the FILE_NAME value used by set_file_name() and load_meta_data() in metagpt/ext/spo/utils/load.py. The vulnerable code joins the attacker-controlled FILE_NAME…

  • CVE-2026-56718HigAug 30, 2026
    risk 0.49cvss 7.5epss 0.01

    AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service that allows unauthenticated remote attackers to read arbitrary files with root privileges by supplying path traversal sequences in the HTTP request URI.…

  • CVE-2026-82286HigAug 28, 2026
    risk 0.49cvss 8.6epss 0.00

    gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthenticated attackers to write arbitrary files to any filesystem path. Attackers can supply absolute paths or parent-directory segments to overwrite existing files…

  • CVE-2026-82275HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Qwen-Agent through 0.0.34 contains a path traversal vulnerability in the document parser that fails to restrict file access to intended directories. Attackers can supply absolute file paths to the unauthenticated Gradio interface to read arbitrary files accessible by the server…

  • CVE-2026-75333HigAug 26, 2026
    risk 0.49cvss 7.5epss 0.00

    yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new File() for file system operations without any path sanitization or whitelist validation.

  • CVE-2026-75328HigAug 26, 2026
    risk 0.49cvss 7.5epss 0.00

    In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java has an arbitrary file read vulnerability:

  • CVE-2026-36851HigAug 26, 2026
    risk 0.49cvss 7.5epss 0.00

    Path traversal vulnerability in UnPoller 2.33.0 password field allows arbitrary file read and network exfiltration.

  • CVE-2026-15990HigAug 26, 2026
    risk 0.49cvss 7.5epss 0.01

    The Formidable Charts plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.0.1 via the 'frm_graph' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can…

  • CVE-2026-55557HigAug 25, 2026
    risk 0.49cvss —epss 0.00

    browse-mcp is a Playwright-based headless-browser MCP server for MCP-capable agents. Prior to 0.8.2, browser_download writes a fetched response body to join(save_dir, filename) without validating the caller-controlled save_dir, while browser_save_state and browser_load_state…

  • CVE-2026-78284HigAug 24, 2026
    risk 0.49cvss 8.6epss 0.00

    Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.