VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,485)

page 370 of 525
  • CVE-2018-1000532MedJun 26, 2018
    risk 0.31cvss 4.7epss 0.00

    beep version 1.3 and up contains a External Control of File Name or Path vulnerability in --device option that can result in Local unprivileged user can inhibit execution of arbitrary programs by other users, allowing DoS. This attack appear to be exploitable via The system must…

  • CVE-2018-5448MedMay 4, 2018
    risk 0.31cvss 4.8epss 0.01

    Medtronic 2090 CareLink Programmer’s software deployment network contains a directory traversal vulnerability that could allow an attacker to read files on the system.

  • CVE-2026-87910MedSep 11, 2026
    risk 0.30cvss —epss 0.01

    When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls,…

  • CVE-2026-82233MedAug 28, 2026
    risk 0.30cvss 5.7epss 0.00

    SiYuan before v3.8.1 contains a path traversal vulnerability in the asset.upload MCP tool that accepts arbitrary absolute file paths without workspace boundary validation. Attackers can induce the AI Agent to upload sensitive files such as SSH keys or credentials from outside…

  • CVE-2026-66484MedAug 10, 2026
    risk 0.30cvss —epss 0.00

    GNU cpio contains a Path Traversal vulnerability in its tar archive extraction functionality. When extracting a tar archive in copy-in mode with the --no-absolute-filenames option, the extracted file name is normalized but the tar hard-link target is passed to the link_to_name…

  • CVE-2026-61432MedJul 10, 2026
    risk 0.30cvss 5.7epss 0.00

    PraisonAI (praisonaiagents) before 1.6.78 contains a path traversal vulnerability in the FastContext feature (praisonaiagents.context.fast). FastContextAgent.execute_tool() prepends the configured workspace_path only for relative paths and neither rejects absolute paths nor…

  • CVE-2026-40605MedJun 4, 2026
    risk 0.30cvss —epss 0.00

    Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.1, a path traversal vulnerability in the cache deletion endpoint allows authenticated API access to delete directories outside the configured cache path. This can cause arbitrary…

  • CVE-2025-12757MedFeb 10, 2026
    risk 0.30cvss 4.6epss 0.00

    An AXIS Camera Station Pro feature can be exploited in a way that allows a non-admin user to view information they are not permitted to.

  • CVE-2026-22625MedJan 30, 2026
    risk 0.30cvss 4.6epss 0.00

    Improper handling of filenames in certain HIKSEMI NAS products may lead to the exposure of sensitive system files.

  • CVE-2025-54292MedOct 2, 2025
    risk 0.30cvss 4.6epss 0.00

    Path traversal in Canonical LXD LXD-UI versions before 6.5 and 5.21.4 on all platforms allows remote authenticated attackers to access or modify unintended resources via crafted resource names embedded in URL paths.

  • CVE-2020-3538MedNov 18, 2024
    risk 0.30cvss 4.6epss 0.01

    A vulnerability in a certain REST API endpoint of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to perform a path traversal attack on an affected device. The vulnerability is due to insufficient path restriction…

  • CVE-2024-34653MedSep 4, 2024
    risk 0.30cvss 4.6epss 0.00

    Path Traversal in My Files prior to SMR Sep-2024 Release 1 allows physical attackers to access directories with My Files' privilege.

  • CVE-2024-25125MedFeb 14, 2024
    risk 0.30cvss 5.3epss 0.30

    Digdag is an open source tool that to build, run, schedule, and monitor complex pipelines of tasks across various platforms. Treasure Data's digdag workload automation system is susceptible to a path traversal vulnerability if it's configured to store log files locally. This…

  • CVE-2024-24565MedJan 30, 2024
    risk 0.30cvss 5.7epss 0.03

    CrateDB is a distributed SQL database that makes it simple to store and analyze massive amounts of data in real-time. There is a COPY FROM function in the CrateDB database that is used to import file data into database tables. This function has a flaw, and authenticated…

  • CVE-2023-6900MedDec 17, 2023
    risk 0.30cvss 4.6epss 0.01

    A vulnerability, which was classified as critical, has been found in rmountjoy92 DashMachine 0.5-4. Affected by this issue is some unknown functionality of the file /settings/delete_file. The manipulation of the argument file leads to path traversal: '../filedir'. The exploit…

  • CVE-2023-3348MedAug 3, 2023
    risk 0.30cvss 5.7epss 0.01

    The Wrangler command line tool  (<[email protected] or <[email protected]) was affected by a directory traversal vulnerability when running a local development server for Pages (wrangler pages dev command). This vulnerability enabled an attacker in the same network as the victim…

  • CVE-2022-41231MedSep 21, 2022
    risk 0.30cvss 5.7epss 0.01

    Jenkins Build-Publisher Plugin 1.22 and earlier allows attackers with Item/Configure permission to create or replace any config.xml file on the Jenkins controller file system by providing a crafted file name to an API endpoint.

  • CVE-2021-22440MedJul 13, 2021
    risk 0.30cvss 4.6epss 0.00

    There is a path traversal vulnerability in some Huawei products. The vulnerability is due to that the software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software…

  • CVE-2020-9106MedOct 12, 2020
    risk 0.30cvss 4.6epss 0.00

    HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) have a path traversal vulnerability. The system does not sufficiently validate certain pathname, successful exploit could allow the attacker access files and cause information disclosure.

  • CVE-2018-1002205MedJul 25, 2018
    risk 0.30cvss 5.5epss 0.10

    DotNetZip.Semvered before 1.11.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.