CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,395)
page 132 of 520| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-28167 | Hig | 0.49 | 7.5 | 0.00 | Aug 24, 2026 | Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions. | ||
| CVE-2026-76357 | Hig | 0.49 | 7.6 | 0.00 | Aug 19, 2026 | In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a crafted file path to the Representational State Transfer (REST) API and execute arbitrary code. The vulnerability is possible because the REST API does not require an assigned role… | ||
| CVE-2026-73181 | Hig | 0.49 | 7.5 | 0.00 | Aug 18, 2026 | Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions. | ||
| CVE-2026-15585 | Hig | 0.49 | 7.5 | 0.00 | Aug 18, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. AKINSOFT Wolvox9 ERP / KontrolPanel.exe allows Path Traversal. This issue affects AKINSOFT Wolvox9 ERP /… | ||
| CVE-2026-67918 | — | Hig | 0.49 | 7.5 | 0.01 | Aug 17, 2026 | Directory Traversal vulnerability in hermes-studio v.0.6.26 allows a remote attacker to obtain sensitive information via the validatePath function in api/hermes/download endpoint | |
| CVE-2026-75482 | Hig | 0.49 | 7.5 | 0.01 | Aug 17, 2026 | SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that joins request paths to the trajectory directory in its /trajectory/ handler without rejecting parent-directory ('..') references, bypassing the built-in path sanitization. The… | ||
| CVE-2026-75111 | Hig | 0.49 | 7.5 | 0.00 | Aug 17, 2026 | Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoint, allowing unauthenticated attackers to read arbitrary files outside the workspace directory. Attackers can supply traversal sequences or absolute paths in the filename field to… | ||
| CVE-2026-50776 | Hig | 0.49 | 7.5 | 0.02 | Aug 17, 2026 | Directory Traversal vulnerability in Pronis Loisirs Billetterie CSE - < 04/2026 allows a remote attacker to obtain sensitive information and execute arbitrary code. | ||
| CVE-2026-18554 | Hig | 0.49 | 7.5 | 0.01 | Aug 14, 2026 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory. | ||
| CVE-2026-16915 | Hig | 0.49 | 7.5 | 0.01 | Aug 14, 2026 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper input validation. | ||
| CVE-2026-17473 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2026 | IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to read arbitrary files due to improper limitation of a pathname to a restricted directory. | ||
| CVE-2026-61980 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2026 | Unauthenticated Arbitrary File Download in OMGF Pro <= 5.2.7 versions. | ||
| CVE-2026-72602 | Hig | 0.49 | 7.5 | 0.00 | Aug 11, 2026 | A path traversal vulnerability in AsyncFuncAI deepwiki-open through commit 16f35a0 allows unauthenticated remote attackers to obtain directory listings for arbitrary filesystem paths via the local-repository structure endpoint. The endpoint accepts an absolute filesystem path… | ||
| CVE-2026-44763 | Hig | 0.49 | 7.6 | 0.00 | Aug 11, 2026 | SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the attacker-influenced content and… | ||
| CVE-2026-72572 | — | Hig | 0.49 | 7.5 | 0.01 | Aug 10, 2026 | A path traversal vulnerability in o1lab/xmysql (all versions) allows an unauthenticated remote attacker to read and download arbitrary files from the server. The lib/xapi.js file at lines 338 and 424 uses the user-controlled req.query.name parameter in path.join(cwd, name)… | |
| CVE-2026-72571 | Hig | 0.49 | 7.5 | 0.01 | Aug 10, 2026 | A path traversal vulnerability in mustafaakin/cast-localvideo (all versions) allows an unauthenticated remote attacker to read arbitrary files from the server. The app.js handler at lines 151-153 passes the user-supplied req.body.dir parameter directly to res.sendFile() without… | ||
| CVE-2026-18427 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2026 | @fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent directory segments, but it did not canonicalize dot segments, duplicate slashes, encoded dots, or backslashes before route matching… | ||
| CVE-2026-71309 | Hig | 0.49 | — | 0.00 | Aug 5, 2026 | rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.40.0 until 1.75.0, rclone serve restic does not correctly reject URL paths beginning with ../ in cmd/serve/restic/restic.go WithRemote, which accepts a leading… | ||
| CVE-2026-61891 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2026 | In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/`, `PUT /files/`) that convert a client-supplied URI directly to a filesystem path and stream the file, without confining it to… | ||
| CVE-2026-46581 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2026 | In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the… |
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions.
- risk 0.49cvss 7.6epss 0.00
In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a crafted file path to the Representational State Transfer (REST) API and execute arbitrary code. The vulnerability is possible because the REST API does not require an assigned role…
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions.
- risk 0.49cvss 7.5epss 0.00
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. AKINSOFT Wolvox9 ERP / KontrolPanel.exe allows Path Traversal. This issue affects AKINSOFT Wolvox9 ERP /…
- risk 0.49cvss 7.5epss 0.01
Directory Traversal vulnerability in hermes-studio v.0.6.26 allows a remote attacker to obtain sensitive information via the validatePath function in api/hermes/download endpoint
- risk 0.49cvss 7.5epss 0.01
SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that joins request paths to the trajectory directory in its /trajectory/ handler without rejecting parent-directory ('..') references, bypassing the built-in path sanitization. The…
- risk 0.49cvss 7.5epss 0.00
Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoint, allowing unauthenticated attackers to read arbitrary files outside the workspace directory. Attackers can supply traversal sequences or absolute paths in the filename field to…
- risk 0.49cvss 7.5epss 0.02
Directory Traversal vulnerability in Pronis Loisirs Billetterie CSE - < 04/2026 allows a remote attacker to obtain sensitive information and execute arbitrary code.
- risk 0.49cvss 7.5epss 0.01
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
- risk 0.49cvss 7.5epss 0.01
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper input validation.
- risk 0.49cvss 7.5epss 0.00
IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to read arbitrary files due to improper limitation of a pathname to a restricted directory.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Arbitrary File Download in OMGF Pro <= 5.2.7 versions.
- risk 0.49cvss 7.5epss 0.00
A path traversal vulnerability in AsyncFuncAI deepwiki-open through commit 16f35a0 allows unauthenticated remote attackers to obtain directory listings for arbitrary filesystem paths via the local-repository structure endpoint. The endpoint accepts an absolute filesystem path…
- risk 0.49cvss 7.6epss 0.00
SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the attacker-influenced content and…
- risk 0.49cvss 7.5epss 0.01
A path traversal vulnerability in o1lab/xmysql (all versions) allows an unauthenticated remote attacker to read and download arbitrary files from the server. The lib/xapi.js file at lines 338 and 424 uses the user-controlled req.query.name parameter in path.join(cwd, name)…
- risk 0.49cvss 7.5epss 0.01
A path traversal vulnerability in mustafaakin/cast-localvideo (all versions) allows an unauthenticated remote attacker to read arbitrary files from the server. The app.js handler at lines 151-153 passes the user-supplied req.body.dir parameter directly to res.sendFile() without…
- risk 0.49cvss 7.5epss 0.00
@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent directory segments, but it did not canonicalize dot segments, duplicate slashes, encoded dots, or backslashes before route matching…
- risk 0.49cvss —epss 0.00
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.40.0 until 1.75.0, rclone serve restic does not correctly reject URL paths beginning with ../ in cmd/serve/restic/restic.go WithRemote, which accepts a leading…
- risk 0.49cvss 7.5epss 0.00
In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/`, `PUT /files/`) that convert a client-supplied URI directly to a filesystem path and stream the file, without confining it to…
- risk 0.49cvss 7.5epss 0.00
In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the…