VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 205 of 520
  • CVE-2026-84667HigSep 2, 2026
    risk 0.46cvss 7.1epss 0.00

    Jenkins ThinBackup Plugin 2.1.4 and earlier allows overwriting the plugin's backup configuration through Stapler data binding, allowing attackers to redirect backup writes to an attacker-specified directory and to include arbitrary files from the Jenkins controller file system…

  • CVE-2026-84201HigSep 1, 2026
    risk 0.46cvss 7.1epss 0.00

    appium-mcp-server through 0.1.61 fails to validate or normalize file paths in the write_file and write_files_batch tools, allowing attackers to write files outside the intended PROJECT_ROOT directory. Attackers can supply absolute paths or relative paths with parent directory…

  • CVE-2026-75594HigAug 31, 2026
    risk 0.46cvss —epss 0.01

    Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler in src/Cms/Media.php allowed Kirby\Cms\Media::thumb() to append a path-bearing filename to a validated parent media directory. On nginx, PHP's…

  • CVE-2026-54083HigAug 28, 2026
    risk 0.46cvss 8.1epss 0.00

    Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. The  ip-customblock  active response script contains a path traversal vulnerability that lets an attacker create or delete arbitrary files on the filesystem…

  • CVE-2026-81730HigAug 27, 2026
    risk 0.46cvss 8.2epss 0.00

    Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the message's MIME headers without reducing it to a safe basename. The global saveAttachment() in htdocs/emailcollector/lib/emailcollector.lib.php builds $filepath = $path . $filename . '.'…

  • CVE-2026-72695HigAug 25, 2026
    risk 0.46cvss 8.1epss 0.01

    Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that allows authenticated users with media management permissions to delete arbitrary files by supplying filenames with directory traversal sequences. The method validates only the…

  • CVE-2026-34968HigAug 25, 2026
    risk 0.46cvss 8.1epss 0.00

    Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the database-list drop action fails to validate file extensions before deletion. An authenticated attacker can submit arbitrary relative file paths in the db[] parameter to delete any…

  • CVE-2026-78381HigAug 24, 2026
    risk 0.46cvss —epss 0.00

    RansomLook contains a path traversal vulnerability in the handling of the screen field associated with group posts. The GroupPost.get API handler concatenates the database-controlled screen value directly with the application's source/ directory and opens the resulting path…

  • CVE-2026-76842HigAug 24, 2026
    risk 0.46cvss 8.2epss 0.00

    The Mercado Pago Node.js SDK interpolates caller-supplied identifiers into API request paths without percent-encoding them, so characters that are structural in a URL survive into the outgoing request. The payment (get, capture, cancel), paymentRefund (create, total, list, get),…

  • CVE-2026-64679HigAug 21, 2026
    risk 0.46cvss 8.1epss 0.01

    Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. From 0.19.8 until 0.45.0, Atlantis does not consistently validate user-controlled workspace values supplied through accepted repository-level atlantis.yaml configuration or…

  • CVE-2026-75115HigAug 21, 2026
    risk 0.46cvss —epss 0.00

    Joomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOtheme Pro 2.3.0-5.0.40 - The Filesystem source's path filter is vulnerable to glob-based pattern attacks, allowing authorized users to read arbitrary files.

  • CVE-2026-76222HigAug 19, 2026
    risk 0.46cvss 8.2epss 0.00

    GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git repositories at arbitrary filesystem paths outside the intended clone directory. Attackers can craft malicious repositories with traversal sequences in submodule…

  • CVE-2026-19589HigAug 17, 2026
    risk 0.46cvss 7.1epss 0.00

    Packer up to 1.15.4 is vulnerable to an issue in the third-party plugin installer that may allow unintended file system modification and could lead to code execution. A user who installs a plugin from a malicious or compromised source may be affected. This vulnerability…

  • CVE-2026-57233HigAug 17, 2026
    risk 0.46cvss 8.1epss 0.01

    Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the WinGup decompress function joins untrusted ZIP entry names to unzipDestTo without canonical containment validation, allowing an entry such as ../mimeTools/mimeTools.dll to overwrite a DLL in a sibling…

  • CVE-2026-19693HigAug 17, 2026
    risk 0.46cvss 8.1epss 0.00

    extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the destination, followed by a regular file…

  • CVE-2026-73659HigAug 13, 2026
    risk 0.46cvss 8.1epss 0.00

    Trigger.dev is the open-source platform for building AI workflows in TypeScript. From 4.4.2 until 4.5.0, the packet presign routes in apps/webapp/app/routes/api.v1.packets.$.ts pass a caller-controlled filename through resolveStoreProtocolForPacketPresign to generatePresignedUrl…

  • CVE-2026-73658HigAug 13, 2026
    risk 0.46cvss 8.2epss 0.00

    Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() and Aws4FetchClient.presign() in apps/webapp/app/v3/objectStoreClient.server.ts assign user-controlled packet keys to URL.pathname,…

  • CVE-2026-70460HigAug 13, 2026
    risk 0.46cvss 8.1epss 0.00

    rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options. Attackers with write access to place a symlink under…

  • CVE-2026-73620HigAug 13, 2026
    risk 0.46cvss 8.1epss 0.00

    GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe options via kwargs. Attackers can use --prefix to overwrite arbitrary files with repository content or -F to read arbitrary files…

  • CVE-2026-66384MedKEVAug 12, 2026
    risk 0.46cvss 5.3epss 0.01

    An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.