VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,481)

page 247 of 525
  • CVE-2026-23484MedMar 23, 2026
    risk 0.42cvss 6.5epss 0.00

    Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the fileName parameter is not filtered, allowing path traversal to write files anywhere on the file system. Moreover, this interface only requires authProcedure (normal user), not…

  • CVE-2026-23482HigMar 23, 2026
    risk 0.42cvss 7.5epss 0.02

    Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the file server endpoint does not perform permission checks on the temp/ path and does not filter path traversal sequences, allowing unauthorized attackers to read arbitrary files on the server. When…

  • CVE-2026-33292HigMar 22, 2026
    risk 0.42cvss 7.5epss 0.01

    WWBN AVideo is an open source video platform. Prior to version 26.0, the HLS streaming endpoint (`view/hls.php`) is vulnerable to a path traversal attack that allows an unauthenticated attacker to stream any private or paid video on the platform. The `videoDirectory` GET…

  • CVE-2019-25610MedMar 22, 2026
    risk 0.42cvss 6.5epss 0.01

    NetNumber Titan Master 7.9.1 contains a path traversal vulnerability in the drp endpoint that allows authenticated users to download arbitrary files by injecting directory traversal sequences. Attackers can manipulate the path parameter with base64-encoded payloads containing…

  • CVE-2019-25574MedMar 21, 2026
    risk 0.42cvss 6.5epss 0.01

    Green CMS 2.x contains a path traversal vulnerability that allows authenticated attackers to download arbitrary files and directories by injecting directory traversal sequences. Attackers can manipulate the theme_name parameter in the themeexporthandle action or supply…

  • CVE-2026-32055HigMar 21, 2026
    risk 0.42cvss 7.6epss 0.00

    OpenClaw versions prior to 2026.2.26 contain a path traversal vulnerability in workspace boundary validation that allows attackers to write files outside the workspace through in-workspace symlinks pointing to non-existent out-of-root targets. The vulnerability exists because…

  • CVE-2026-33476HigMar 20, 2026
    risk 0.42cvss 7.5epss 0.03

    SiYuan is a personal knowledge management system. Prior to version 3.6.2, the Siyuan kernel exposes an unauthenticated file-serving endpoint under `/appearance/*filepath.` Due to improper path sanitization, attackers can perform directory traversal and read arbitrary files…

  • CVE-2026-2421MedMar 20, 2026
    risk 0.42cvss 6.5epss 0.01

    The ilGhera Carta Docente for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.0 via the 'cert' parameter of the 'wccd-delete-certificate' AJAX action. This is due to insufficient file path validation before performing a…

  • CVE-2026-32030HigMar 19, 2026
    risk 0.42cvss 7.5epss 0.01

    OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the stageSandboxMedia function that accepts arbitrary absolute paths when iMessage remote attachment fetching is enabled. An attacker who can tamper with attachment path metadata can disclose files…

  • CVE-2026-32749HigMar 19, 2026
    risk 0.42cvss 7.6epss 0.01

    SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importSY and POST /api/import/importZipMd write uploaded archives to a path derived from the multipart filename field without sanitization, allowing an admin to write files to…

  • CVE-2025-67115MedMar 19, 2026
    risk 0.42cvss 6.5epss 0.00

    A path traversal vulnerability in /ftl/web/setup.cgi in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote authenticated users to read arbitrary files from the filesystem via crafted values in the log_type parameter to…

  • CVE-2026-30403HigMar 19, 2026
    risk 0.42cvss 7.5epss 0.01

    There is an arbitrary file read vulnerability in the test connection function of backend database management in wgcloud v3.6.3 and before, which can be used to read any file on the victim's server.

  • CVE-2026-3029HigMar 19, 2026
    risk 0.42cvss 7.5epss 0.00

    A path traversal and arbitrary file write vulnerability exist in the embedded get function in '_main_.py' in PyMuPDF version, 1.26.5.

  • CVE-2026-32805HigMar 18, 2026
    risk 0.42cvss 7.5epss 0.01

    Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for functional and integration tests within GitHub Actions. Prior to version 0.2.2, the `sanitizeArchivePath` function in `webserver/api/v1/decoder.go` (lines 80-88) is…

  • CVE-2026-32981HigMar 17, 2026
    risk 0.42cvss 7.5epss 0.01

    A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due to improper validation and sanitization of user-supplied paths in the static file handling mechanism, an attacker can use traversal sequences (e.g., ../) to…

  • CVE-2026-21005MedMar 16, 2026
    risk 0.42cvss 6.5epss 0.00

    Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Smart Switch privilege.

  • CVE-2026-32274HigMar 12, 2026
    risk 0.42cvss 7.5epss 0.01

    Black is the uncompromising Python code formatter. Starting in version 24.3.0 and prior to version 26.3.1, Black writes a cache file, the name of which is computed from various formatting options. The value of the --python-cell-magics option was placed in the filename without…

  • CVE-2026-3954MedMar 11, 2026
    risk 0.42cvss 6.5epss 0.01

    A weakness has been identified in OpenBMB XAgent 1.0.0. Affected by this vulnerability is the function workspace of the file XAgentServer/application/routers/workspace.py. This manipulation of the argument file_name causes path traversal. The attack may be initiated remotely.…

  • CVE-2026-30234MedMar 11, 2026
    risk 0.42cvss 6.5epss 0.00

    OpenProject is an open-source, web-based project management software. Prior to 17.2.0, an authenticated project member with BCF import permissions can upload a crafted .bcf archive where the value in markup.bcf is manipulated to contain an absolute or traversal local…

  • CVE-2026-28807HigMar 10, 2026
    risk 0.42cvss 7.5epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in gleam-wisp wisp allows arbitrary file read via percent-encoded path traversal. The wisp.serve_static function is vulnerable to path traversal because sanitization runs before…