VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,485)

page 390 of 525
  • CVE-2016-4320MedApr 10, 2017
    risk 0.28cvss 4.3epss 0.02

    Atlassian Bitbucket Server before 4.7.1 allows remote attackers to read the first line of an arbitrary file via a directory traversal attack on the pull requests resource.

  • CVE-2016-6370MedSep 12, 2016
    risk 0.28cvss 4.3epss 0.02

    Directory traversal vulnerability in the web interface in Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) 10.6(3) and earlier allows remote authenticated users to read arbitrary files via a crafted pathname in an HTTP request, aka Bug ID CSCuz27255.

  • CVE-2016-5664MedAug 26, 2016
    risk 0.28cvss 4.3epss 0.02

    Directory traversal vulnerability on Accellion Kiteworks appliances before kw2016.03.00 allows remote attackers to read files via a crafted URI.

  • CVE-2016-5307MedJun 30, 2016
    risk 0.28cvss 4.3epss 0.03

    Directory traversal vulnerability in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to read arbitrary files in the web-root directory tree via unspecified vectors.

  • CVE-2016-1192MedJun 19, 2016
    risk 0.28cvss 4.3epss 0.01

    Directory traversal vulnerability in the logging implementation in Cybozu Garoon 3.7 through 4.2 allows remote authenticated users to read a log file via unspecified vectors.

  • CVE-2016-2097MedApr 7, 2016
    risk 0.28cvss 5.3epss 0.04

    Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.2 and 4.x before 4.1.14.2 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname. NOTE: this…

  • CVE-2026-107844MedOct 9, 2026
    risk 0.27cvss 5.3epss —

    Contao is an Open Source CMS. From version 5.0.0 until 5.3.50 and 5.7.12, ImagesController joins the user-controlled {path} parameter to the configured image target directory with Path::join() but does not use Path::isBasePath() to verify that the canonical path remains inside…

  • CVE-2026-106508MedOct 6, 2026
    risk 0.27cvss 5.3epss 0.00

    Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by potential file exposure through local techdocs publisher. When using the local TechDocs publisher (techdocs.publisher.type: 'local'), it was…

  • CVE-2026-55156MedSep 28, 2026
    risk 0.27cvss 5.3epss 0.00

    Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge graph across 16 CLI clients. Prior to version 5.1.0, the dashboard HTTP server in token-optimizer-mcp exposes /api/session-summary and /api/session-events with no…

  • CVE-2026-100533MedSep 26, 2026
    risk 0.27cvss 5.3epss 0.00

    OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in the tools.fs.workspaceOnly feature where Unicode filename fallback can normalize validated parent directory components. Admitted requesters can exploit canonically equivalent sibling directories to read…

  • CVE-2026-65829MedSep 22, 2026
    risk 0.27cvss 5.3epss 0.00

    MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 7.3.0 until 16.5.0, reading a suitably crafted Primavera P3 PRX or SureTrak STX file can cause MPXJ to write files to arbitrary locations in the filesystem. This…

  • CVE-2026-92131MedSep 16, 2026
    risk 0.27cvss 4.2epss 0.00

    Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to the library Pipeline step to a relative path inside the SCM checkout, and follows symbolic links to locations outside of the SCM checkout when retrieving the…

  • CVE-2026-50024MedSep 15, 2026
    risk 0.27cvss 5.3epss 0.00

    GitHacker is a tool that restores Git repositories from exposed .git directories. In 1.1.7 and earlier, add_head_file_tasks parses an attacker-controlled ref path from .git/HEAD and joins unvalidated path segments onto temp_dst/.git/logs/, allowing a malicious server to make…

  • CVE-2026-47256MedSep 14, 2026
    risk 0.27cvss 5.3epss 0.00

    OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs. Prior to 0.154.0, the Sentry exporter reads the remote OTLP sender-controlled…

  • CVE-2026-88046MedSep 10, 2026
    risk 0.27cvss 5.3epss 0.00

    rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone core does not reject parent-directory segments in source Object.Remote() values before fs/list, fs/walk, fs/sync, and fs/operations pass those…

  • CVE-2026-88940MedSep 10, 2026
    risk 0.27cvss 5.3epss 0.01

    knowns through 0.33.0 fails to validate the path query parameter in the workspace browse endpoint, allowing remote attackers to enumerate arbitrary directories on the host filesystem. Attackers can traverse the directory structure to locate project directories and identify…

  • CVE-2026-82521MedSep 3, 2026
    risk 0.27cvss 5.3epss 0.00

    parsedmarc 9.0.6 before 11.0.1 writes forensic report sample files using an output path derived from the email subject. When the subject consists entirely of path traversal sequences, the filename sanitization function produces an empty string, and a fallback to the raw…

  • CVE-2026-81716MedAug 27, 2026
    risk 0.27cvss 5.2epss 0.00

    openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 contain a path traversal flaw in PluginSandbox._is_safe_path, which authorized file access using a bare string-prefix match. A sandboxed plugin without the READ_FILES permission could read or write another plugin's…

  • CVE-2026-53452MedAug 19, 2026
    risk 0.27cvss 5.3epss 0.01

    Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated configure-sdr Socket.IO command accepts a recordingPath for the sigmf-playback SDR and…

  • CVE-2026-48796MedAug 18, 2026
    risk 0.27cvss 5.3epss 0.00

    CefSharp provides .NET bindings for the Chromium Embedded Framework for Windows Forms and Windows Presentation Foundation applications. Prior to version 148.0.90, CefSharp/SchemeHandler/FolderSchemeHandlerFactory.cs used filePath.StartsWith(rootFolder,…