CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,483)
page 291 of 525| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-11798 | Med | 0.41 | 5.3 | 0.49 | Jun 10, 2020 | A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an attacker to access arbitrary files from restricted directories of the server via a crafted URL, due to insufficient access validation. A… | ||
| CVE-2018-1797 | Med | 0.41 | 6.3 | 0.02 | Nov 16, 2018 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using Enterprise bundle Archives (EBA) could allow a local attacker to traverse directories on the system. By persuading a victim to extract a specially-crafted ZIP archive containing "dot dot slash" sequences (../), an… | ||
| CVE-2018-16133 | Med | 0.41 | 5.3 | 0.39 | Aug 29, 2018 | Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI. | ||
| CVE-2014-8676 | Med | 0.41 | 5.3 | 0.41 | Aug 31, 2017 | Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in a URL path parameter. | ||
| CVE-2016-10039 | Hig | 0.41 | 7.3 | 0.02 | Dec 24, 2016 | Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/getfiles. | ||
| CVE-2016-10038 | Hig | 0.41 | 7.3 | 0.02 | Dec 24, 2016 | Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/remove. | ||
| CVE-2016-10037 | Hig | 0.41 | 7.3 | 0.02 | Dec 24, 2016 | Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted id (aka dir) parameter, related to browser/directory/getlist. | ||
| CVE-2026-107716 | Hig | 0.40 | — | — | Oct 8, 2026 | Banks generates meaningful LLM prompts using a simple template language. Prior to 2.5.1, Banks DirectoryPromptRegistry does not reject symbolic links for index.json or discovered and existing .jinja prompt files. In an application where untrusted users can influence a prompt… | ||
| CVE-2026-105677 | Hig | 0.40 | 7.2 | 0.01 | Oct 5, 2026 | Ghost is a Node.js content management system. From 6.10.3 until 6.64.0, a vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to execute arbitrary code on the server via a crafted theme. This issue is fixed in version 6.64.0. | ||
| CVE-2026-101066 | Hig | 0.40 | 7.3 | 0.01 | Sep 28, 2026 | A vulnerability was determined in dbgate up to 7.3.1. The impacted element is the function createLink of the file packages/api/src/controllers/archive.js of the component Archive Link Creation. This manipulation of the argument linkedFolder causes path traversal. The attack may… | ||
| CVE-2026-100372 | Hig | 0.40 | 7.2 | 0.01 | Sep 25, 2026 | ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor that allows authenticated administrators to overwrite PHP files by supplying directory traversal sequences in the folder parameter. Attackers with manage_template_access… | ||
| CVE-2026-53554 | Hig | 0.40 | — | 0.00 | Sep 17, 2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/parseExcel endpoint in backend/apps/datasource/api/datasource.py uses attacker-controlled multipart filename data when selecting where uploaded content… | ||
| CVE-2026-89038 | Med | 0.40 | 6.2 | 0.00 | Sep 17, 2026 | Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co-resident malicious applications to write attacker-controlled bytes outside the intended staging directory by supplying a crafted _display_name value… | ||
| CVE-2026-47253 | Hig | 0.40 | 7.3 | 0.00 | Sep 14, 2026 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, the clear_plugin_cache(plugin) SQL scalar function in namespace/other_functions.go passes the caller-controlled plugin parameter through path.Join to os.RemoveAll without rejecting traversal segments. A… | ||
| CVE-2026-56839 | Hig | 0.40 | 7.3 | 0.00 | Sep 14, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.6.59, the CODE_TOOLS wrappers keep _workspace_root as None and pass workspace=None to read_file, search_replace, and apply_diff helpers that enforce path containment only for a truthy workspace. An application that exposes… | ||
| CVE-2026-78590 | Hig | 0.40 | 7.3 | 0.00 | Sep 2, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet Settings write access could cause… | ||
| CVE-2026-78592 | Hig | 0.40 | 7.3 | 0.00 | Sep 1, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Kibana can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding tag creation privileges could cause a subsequent… | ||
| CVE-2026-75593 | Hig | 0.40 | — | 0.01 | Aug 19, 2026 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.2, a custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory.… | ||
| CVE-2026-46343 | Hig | 0.40 | 7.2 | 0.00 | Aug 19, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, WazuhCommon.end_receiving_file() in framework/wazuh/core/cluster/common.py allows a cluster-authenticated node to delete files outside… | ||
| CVE-2026-19762 | Hig | 0.40 | 7.3 | 0.01 | Aug 14, 2026 | A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function Paths.ge of the file FileChunkController.java of the component Chunk-Check Endpoint. The manipulation of the argument Name results in path traversal. The attack may be launched… |
- risk 0.41cvss 5.3epss 0.49
A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an attacker to access arbitrary files from restricted directories of the server via a crafted URL, due to insufficient access validation. A…
- risk 0.41cvss 6.3epss 0.02
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using Enterprise bundle Archives (EBA) could allow a local attacker to traverse directories on the system. By persuading a victim to extract a specially-crafted ZIP archive containing "dot dot slash" sequences (../), an…
- risk 0.41cvss 5.3epss 0.39
Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI.
- risk 0.41cvss 5.3epss 0.41
Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in a URL path parameter.
- risk 0.41cvss 7.3epss 0.02
Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/getfiles.
- risk 0.41cvss 7.3epss 0.02
Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/remove.
- risk 0.41cvss 7.3epss 0.02
Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted id (aka dir) parameter, related to browser/directory/getlist.
- risk 0.40cvss —epss —
Banks generates meaningful LLM prompts using a simple template language. Prior to 2.5.1, Banks DirectoryPromptRegistry does not reject symbolic links for index.json or discovered and existing .jinja prompt files. In an application where untrusted users can influence a prompt…
- risk 0.40cvss 7.2epss 0.01
Ghost is a Node.js content management system. From 6.10.3 until 6.64.0, a vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to execute arbitrary code on the server via a crafted theme. This issue is fixed in version 6.64.0.
- risk 0.40cvss 7.3epss 0.01
A vulnerability was determined in dbgate up to 7.3.1. The impacted element is the function createLink of the file packages/api/src/controllers/archive.js of the component Archive Link Creation. This manipulation of the argument linkedFolder causes path traversal. The attack may…
- risk 0.40cvss 7.2epss 0.01
ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor that allows authenticated administrators to overwrite PHP files by supplying directory traversal sequences in the folder parameter. Attackers with manage_template_access…
- risk 0.40cvss —epss 0.00
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/parseExcel endpoint in backend/apps/datasource/api/datasource.py uses attacker-controlled multipart filename data when selecting where uploaded content…
- risk 0.40cvss 6.2epss 0.00
Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co-resident malicious applications to write attacker-controlled bytes outside the intended staging directory by supplying a crafted _display_name value…
- risk 0.40cvss 7.3epss 0.00
Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, the clear_plugin_cache(plugin) SQL scalar function in namespace/other_functions.go passes the caller-controlled plugin parameter through path.Join to os.RemoveAll without rejecting traversal segments. A…
- risk 0.40cvss 7.3epss 0.00
PraisonAI is a multi-agent teams system. Prior to 4.6.59, the CODE_TOOLS wrappers keep _workspace_root as None and pass workspace=None to read_file, search_replace, and apply_diff helpers that enforce path containment only for a truthy workspace. An application that exposes…
- risk 0.40cvss 7.3epss 0.00
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet Settings write access could cause…
- risk 0.40cvss 7.3epss 0.00
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Kibana can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding tag creation privileges could cause a subsequent…
- risk 0.40cvss —epss 0.01
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.2, a custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory.…
- risk 0.40cvss 7.2epss 0.00
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, WazuhCommon.end_receiving_file() in framework/wazuh/core/cluster/common.py allows a cluster-authenticated node to delete files outside…
- risk 0.40cvss 7.3epss 0.01
A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function Paths.ge of the file FileChunkController.java of the component Chunk-Check Endpoint. The manipulation of the argument Name results in path traversal. The attack may be launched…