VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,481)

page 225 of 525
  • CVE-2026-92812MedSep 16, 2026
    risk 0.44cvss 6.8epss 0.00

    decap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix comparison without path separator validation. Attackers can access sibling directories whose names begin with the repository directory name to read, write, or…

  • CVE-2026-59974HigSep 16, 2026
    risk 0.44cvss 7.8epss 0.00

    Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.14.0, stanza.resources.common.unzip in stanza/resources/common.py passes downloaded model and resource archives to zipfile.ZipFile.extractall…

  • CVE-2026-76555MedSep 16, 2026
    risk 0.44cvss 6.8epss 0.00

    The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a user-supplied file path before reading it and copying it into a publicly accessible directory, allowing any user whose role an administrator has granted the WP Import Export Lite WordPress plugin before…

  • CVE-2026-82427HigSep 14, 2026
    risk 0.44cvss 7.8epss 0.00

    Description A topology's `topology.blobstore.map` lets the submitter choose a local name for each blob that the supervisor localises. That name was used to build a path under the topology's working directory without normalisation, in both `AsyncLocalizer` and…

  • CVE-2026-74859MedSep 8, 2026
    risk 0.44cvss 6.8epss 0.00

    The shell theme installer in gnome-tweaks extracts user-supplied ZIP archives without validating archive member paths. As a result, a crafted theme archive can write files outside ~/.themes by using ../ path traversal, absolute paths, or symlink entries.

  • CVE-2026-61753HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.01

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-78275MedAug 27, 2026
    risk 0.44cvss 6.8epss 0.01

    Editor Arbitrary File Deletion in Fluent Boards Pro <= 2.0.11 versions.

  • CVE-2026-18849MedAug 19, 2026
    risk 0.44cvss 6.8epss 0.00

    IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update process. An attacker with authenticated administrator-level access to the BMC can, under specific conditions, execute arbitrary code, resulting in a confidentiality, integrity, and…

  • CVE-2026-57471MedAug 14, 2026
    risk 0.44cvss —epss 0.00

    Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the file management functionality of the XML-RPC management interface of KUNBUS RevPiPyLoad in version 0.11.0 that allows a local…

  • CVE-2026-65939MedAug 12, 2026
    risk 0.44cvss 6.8epss 0.00

    In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.

  • CVE-2026-73234HigAug 11, 2026
    risk 0.44cvss 7.8epss 0.00

    FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, PropertyFileIncluded::Restore() in src/App/PropertyFile.cpp concatenates an attacker-controlled file or data attribute from Document.xml with the document transient path without rejecting…

  • CVE-2026-71475MedAug 11, 2026
    risk 0.44cvss 6.8epss 0.01

    A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL path. This occurs because the ClusterID, which is controlled by the spoke, is used directly in the request path without proper…

  • CVE-2026-55747MedAug 5, 2026
    risk 0.44cvss 6.8epss 0.00

    The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow implements a helper as a thin os.path.join(workdir, p) wrapper with no canonicalization or containment check, used unguarded by the ReadFile, ListFiles, PatchRead, and PatchApply file-access tools. Severity…

  • CVE-2026-48338MedJul 14, 2026
    risk 0.44cvss 6.8epss 0.00

    ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended…

  • CVE-2026-55878HigJul 8, 2026
    risk 0.44cvss 7.8epss 0.00

    Symfony UX is a JavaScript ecosystem for Symfony. From 2.32.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux:install console command installs files from a recipe kit by copying paths listed in a copy-files map, and because Path::isRelative() accepts paths like ../../../etc, a…

  • CVE-2026-11940HigJun 23, 2026
    risk 0.44cvss —epss 0.01

    tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself.  The extraction fallback validated the symlink at it's archived location but recreated it at…

  • CVE-2026-43901MedMay 11, 2026
    risk 0.44cvss 6.8epss 0.00

    Wireshark MCP is an MCP Server that turns tshark into a structured analysis interface, then layers in optional Wireshark suite utilities. In 1.1.5 and earlier, wireshark-mcp exposes a wireshark_export_objects MCP tool that accepts an attacker-controlled dest_dir parameter and…

  • CVE-2026-25691MedApr 14, 2026
    risk 0.44cvss 6.7epss 0.00

    A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4, FortiSandbox PaaS 5.0.4 may allow a privileged…

  • CVE-2026-32146HigApr 11, 2026
    risk 0.44cvss 7.8epss 0.00

    Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows arbitrary file system modification during dependency download. Dependency names from gleam.toml and manifest.toml are incorporated into filesystem paths without sufficient…

  • CVE-2025-59709MedApr 3, 2026
    risk 0.44cvss 6.8epss 0.01

    An issue was discovered in Biztalk360 through 11.5. because of mishandling of user-provided input in a path to be read by the server, a Super User attacker is able to read files on the system and/or coerce an authentication from the service, aka Directory Traversal.