VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 132 of 520
  • CVE-2026-28167HigAug 24, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions.

  • CVE-2026-76357HigAug 19, 2026
    risk 0.49cvss 7.6epss 0.00

    In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a crafted file path to the Representational State Transfer (REST) API and execute arbitrary code. The vulnerability is possible because the REST API does not require an assigned role…

  • CVE-2026-73181HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions.

  • CVE-2026-15585HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. AKINSOFT Wolvox9 ERP / KontrolPanel.exe allows Path Traversal. This issue affects AKINSOFT Wolvox9 ERP /…

  • CVE-2026-67918HigAug 17, 2026
    risk 0.49cvss 7.5epss 0.01

    Directory Traversal vulnerability in hermes-studio v.0.6.26 allows a remote attacker to obtain sensitive information via the validatePath function in api/hermes/download endpoint

  • CVE-2026-75482HigAug 17, 2026
    risk 0.49cvss 7.5epss 0.01

    SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that joins request paths to the trajectory directory in its /trajectory/ handler without rejecting parent-directory ('..') references, bypassing the built-in path sanitization. The…

  • CVE-2026-75111HigAug 17, 2026
    risk 0.49cvss 7.5epss 0.00

    Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoint, allowing unauthenticated attackers to read arbitrary files outside the workspace directory. Attackers can supply traversal sequences or absolute paths in the filename field to…

  • CVE-2026-50776HigAug 17, 2026
    risk 0.49cvss 7.5epss 0.02

    Directory Traversal vulnerability in Pronis Loisirs Billetterie CSE - < 04/2026 allows a remote attacker to obtain sensitive information and execute arbitrary code.

  • CVE-2026-18554HigAug 14, 2026
    risk 0.49cvss 7.5epss 0.01

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.

  • CVE-2026-16915HigAug 14, 2026
    risk 0.49cvss 7.5epss 0.01

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper input validation.

  • CVE-2026-17473HigAug 13, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to read arbitrary files due to improper limitation of a pathname to a restricted directory.

  • CVE-2026-61980HigAug 13, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Arbitrary File Download in OMGF Pro <= 5.2.7 versions.

  • CVE-2026-72602HigAug 11, 2026
    risk 0.49cvss 7.5epss 0.00

    A path traversal vulnerability in AsyncFuncAI deepwiki-open through commit 16f35a0 allows unauthenticated remote attackers to obtain directory listings for arbitrary filesystem paths via the local-repository structure endpoint. The endpoint accepts an absolute filesystem path…

  • CVE-2026-44763HigAug 11, 2026
    risk 0.49cvss 7.6epss 0.00

    SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the attacker-influenced content and…

  • CVE-2026-72572HigAug 10, 2026
    risk 0.49cvss 7.5epss 0.01

    A path traversal vulnerability in o1lab/xmysql (all versions) allows an unauthenticated remote attacker to read and download arbitrary files from the server. The lib/xapi.js file at lines 338 and 424 uses the user-controlled req.query.name parameter in path.join(cwd, name)…

  • CVE-2026-72571HigAug 10, 2026
    risk 0.49cvss 7.5epss 0.01

    A path traversal vulnerability in mustafaakin/cast-localvideo (all versions) allows an unauthenticated remote attacker to read arbitrary files from the server. The app.js handler at lines 151-153 passes the user-supplied req.body.dir parameter directly to res.sendFile() without…

  • CVE-2026-18427HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.00

    @fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent directory segments, but it did not canonicalize dot segments, duplicate slashes, encoded dots, or backslashes before route matching…

  • CVE-2026-71309HigAug 5, 2026
    risk 0.49cvss —epss 0.00

    rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.40.0 until 1.75.0, rclone serve restic does not correctly reject URL paths beginning with ../ in cmd/serve/restic/restic.go WithRemote, which accepts a leading…

  • CVE-2026-61891HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/`, `PUT /files/`) that convert a client-supplied URI directly to a filesystem path and stream the file, without confining it to…

  • CVE-2026-46581HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the…