VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,485)

page 395 of 525
  • CVE-2025-43250MedJul 30, 2025
    risk 0.26cvss 4.0epss 0.00

    A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to break out of its sandbox.

  • CVE-2025-43206MedJul 30, 2025
    risk 0.26cvss 4.0epss 0.00

    A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access protected user data.

  • CVE-2024-22231MedJun 27, 2024
    risk 0.26cvss 5.0epss 0.01

    Syndic cache directory creation is vulnerable to a directory traversal attack in salt project which can lead a malicious attacker to create an arbitrary directory on a Salt master.

  • CVE-2024-36795MedJun 6, 2024
    risk 0.26cvss 4.0epss 0.00

    Insecure permissions in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to access URLs and directories embedded within the firmware via unspecified vectors.

  • CVE-2024-20804MedJan 4, 2024
    risk 0.26cvss 4.0epss 0.00

    Path traversal vulnerability in FileUriConverter of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file.

  • CVE-2023-35887MedJul 10, 2023
    risk 0.26cvss 5.0epss 0.01

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA. In SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to discover "exists/does not exist" information about…

  • CVE-2022-4885MedJan 11, 2023
    risk 0.26cvss 5.0epss 0.01

    A vulnerability has been found in sviehb jefferson up to 0.3 and classified as critical. This vulnerability affects unknown code of the file src/scripts/jefferson. The manipulation leads to path traversal. The attack can be initiated remotely. The complexity of an attack is…

  • CVE-2022-36850MedSep 9, 2022
    risk 0.26cvss 4.0epss 0.00

    Path traversal vulnerability in CallBGProvider prior to SMR Sep-2022 Release 1 allows attacker to overwrite arbitrary file with phone uid.

  • CVE-2022-33690MedJul 12, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper input validation in Contacts Storage prior to SMR Jul-2022 Release 1 allows attacker to access arbitrary file.

  • CVE-2022-28784MedMay 3, 2022
    risk 0.26cvss 4.0epss 0.00

    Path traversal vulnerability in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to list file names in arbitrary directory as system user. The patch addresses incorrect implementation of file path validation check logic.

  • CVE-2022-28543MedApr 11, 2022
    risk 0.26cvss 4.0epss 0.00

    Path traversal vulnerability in Samsung Flow prior to version 4.8.07.4 allows local attackers to read arbitrary files as Samsung Flow permission.

  • CVE-2021-32842MedJan 26, 2022
    risk 0.26cvss 4.0epss 0.01

    SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Starting version 1.0.0 and prior to version 1.3.3, a check was added if the destination file is under a destination directory. However, it is not enforced that `_baseDirectory` ends with slash. If the _baseDirectory…

  • CVE-2020-15703MedOct 31, 2020
    risk 0.26cvss 4.0epss 0.00

    There is no input validation on the Locale property in an apt transaction. An unprivileged user can supply a full path to a writable directory, which lets aptd read a file as root. Having a symlink in place results in an error message if the file exists, and no error otherwise.…

  • CVE-2026-105676MedOct 5, 2026
    risk 0.25cvss 4.9epss 0.00

    Ghost is a Node.js content management system. From 1.20.0 until 6.64.0, a vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to read JSON files outside of the active theme's directory, potentially exposing server configuration…

  • CVE-2025-69904MedSep 11, 2026
    risk 0.25cvss 4.9epss 0.00

    Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, which allows an administrator to read arbitrary files on the server by manipulating file path input. Successful exploitation may lead to unauthorized access to sensitive system or application files.

  • CVE-2026-52832MedSep 2, 2026
    risk 0.25cvss 4.9epss 0.01

    Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio Dashboard exposes POST /api/functions without authentication by default (NOP auth mode). The spec.handler field (e.g., mymodule:myfunction) is parsed by…

  • CVE-2026-63179MedAug 26, 2026
    risk 0.25cvss 4.9epss 0.01

    Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, authenticated backend users can disclose arbitrary files readable by the PHP process by injecting @import (inline) directives into LESS source that the backend…

  • CVE-2026-79773MedAug 25, 2026
    risk 0.25cvss 4.9epss 0.00

    Winter CMS before 1.2.13 contains a local file inclusion vulnerability in the JavascriptImporter filter that allows authenticated users with cms.manage_assets permission to disclose arbitrary server-readable files by placing =include or =require directives in theme JavaScript…

  • CVE-2026-78435LowAug 24, 2026
    risk 0.25cvss 3.8epss 0.01

    A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the component Logo Handler. Such manipulation of the argument data1 leads to path traversal. The attack can be…

  • CVE-2026-72820MedAug 14, 2026
    risk 0.25cvss 4.9epss 0.01

    Grav versions before 2.0.13 fail to properly validate backup profile root paths, allowing attackers to archive directories outside GRAV_ROOT when not in the hard-coded deny-list. Attackers with profile editor access can configure backup profiles with traversal paths to expose…