VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,483)

page 291 of 525
  • CVE-2020-11798MedJun 10, 2020
    risk 0.41cvss 5.3epss 0.49

    A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an attacker to access arbitrary files from restricted directories of the server via a crafted URL, due to insufficient access validation. A…

  • CVE-2018-1797MedNov 16, 2018
    risk 0.41cvss 6.3epss 0.02

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using Enterprise bundle Archives (EBA) could allow a local attacker to traverse directories on the system. By persuading a victim to extract a specially-crafted ZIP archive containing "dot dot slash" sequences (../), an…

  • CVE-2018-16133MedAug 29, 2018
    risk 0.41cvss 5.3epss 0.39

    Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI.

  • CVE-2014-8676MedAug 31, 2017
    risk 0.41cvss 5.3epss 0.41

    Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in a URL path parameter.

  • CVE-2016-10039HigDec 24, 2016
    risk 0.41cvss 7.3epss 0.02

    Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/getfiles.

  • CVE-2016-10038HigDec 24, 2016
    risk 0.41cvss 7.3epss 0.02

    Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/remove.

  • CVE-2016-10037HigDec 24, 2016
    risk 0.41cvss 7.3epss 0.02

    Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted id (aka dir) parameter, related to browser/directory/getlist.

  • CVE-2026-107716HigOct 8, 2026
    risk 0.40cvss —epss —

    Banks generates meaningful LLM prompts using a simple template language. Prior to 2.5.1, Banks DirectoryPromptRegistry does not reject symbolic links for index.json or discovered and existing .jinja prompt files. In an application where untrusted users can influence a prompt…

  • CVE-2026-105677HigOct 5, 2026
    risk 0.40cvss 7.2epss 0.01

    Ghost is a Node.js content management system. From 6.10.3 until 6.64.0, a vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to execute arbitrary code on the server via a crafted theme. This issue is fixed in version 6.64.0.

  • CVE-2026-101066HigSep 28, 2026
    risk 0.40cvss 7.3epss 0.01

    A vulnerability was determined in dbgate up to 7.3.1. The impacted element is the function createLink of the file packages/api/src/controllers/archive.js of the component Archive Link Creation. This manipulation of the argument linkedFolder causes path traversal. The attack may…

  • CVE-2026-100372HigSep 25, 2026
    risk 0.40cvss 7.2epss 0.01

    ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor that allows authenticated administrators to overwrite PHP files by supplying directory traversal sequences in the folder parameter. Attackers with manage_template_access…

  • CVE-2026-53554HigSep 17, 2026
    risk 0.40cvss —epss 0.00

    SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/parseExcel endpoint in backend/apps/datasource/api/datasource.py uses attacker-controlled multipart filename data when selecting where uploaded content…

  • CVE-2026-89038MedSep 17, 2026
    risk 0.40cvss 6.2epss 0.00

    Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co-resident malicious applications to write attacker-controlled bytes outside the intended staging directory by supplying a crafted _display_name value…

  • CVE-2026-47253HigSep 14, 2026
    risk 0.40cvss 7.3epss 0.00

    Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, the clear_plugin_cache(plugin) SQL scalar function in namespace/other_functions.go passes the caller-controlled plugin parameter through path.Join to os.RemoveAll without rejecting traversal segments. A…

  • CVE-2026-56839HigSep 14, 2026
    risk 0.40cvss 7.3epss 0.00

    PraisonAI is a multi-agent teams system. Prior to 4.6.59, the CODE_TOOLS wrappers keep _workspace_root as None and pass workspace=None to read_file, search_replace, and apply_diff helpers that enforce path containment only for a truthy workspace. An application that exposes…

  • CVE-2026-78590HigSep 2, 2026
    risk 0.40cvss 7.3epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet Settings write access could cause…

  • CVE-2026-78592HigSep 1, 2026
    risk 0.40cvss 7.3epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Kibana can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding tag creation privileges could cause a subsequent…

  • CVE-2026-75593HigAug 19, 2026
    risk 0.40cvss —epss 0.01

    BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.2, a custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory.…

  • CVE-2026-46343HigAug 19, 2026
    risk 0.40cvss 7.2epss 0.00

    Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, WazuhCommon.end_receiving_file() in framework/wazuh/core/cluster/common.py allows a cluster-authenticated node to delete files outside…

  • CVE-2026-19762HigAug 14, 2026
    risk 0.40cvss 7.3epss 0.01

    A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function Paths.ge of the file FileChunkController.java of the component Chunk-Check Endpoint. The manipulation of the argument Name results in path traversal. The attack may be launched…