VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,485)

page 402 of 525
  • CVE-2021-44111MedFeb 11, 2022
    risk 0.22cvss 4.4epss 0.00

    A Directory Traversal vulnerability exists in S-Cart 6.7 via download in sc-admin/backup.

  • CVE-2021-43840MedDec 17, 2021
    risk 0.22cvss 4.4epss 0.02

    message_bus is a messaging bus for Ruby processes and web clients. In versions prior to 3.3.7 users who deployed message bus with diagnostics features enabled (default off) are vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine…

  • CVE-2020-16116LowAug 3, 2020
    risk 0.22cvss 3.3epss 0.02

    In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the extraction directory via ../ directory traversal.

  • CVE-2018-0660LowSep 7, 2018
    risk 0.22cvss 3.3epss 0.01

    Directory traversal vulnerability in ver.2.8.4.0 and earlier and ver.3.3.0.0 and earlier allows an attacker to create arbitrary files via specially crafted ATC file.

  • CVE-2026-85272MedSep 18, 2026
    risk 0.21cvss 4.3epss 0.00

    Open edX Platform enables the authoring and delivery of online learning at any scale. From Aspen.1 until Ulmo and Verawood.1, openedx/core/lib/extract_archive.py uses _is_bad_path to validate safe_extractall targets by comparing resolved path strings with startswith instead of…

  • CVE-2026-93013MedSep 17, 2026
    risk 0.21cvss 4.3epss 0.01

    RAGFlow through 0.27.2 contains a path traversal vulnerability in the dev_insert_chunks_from_file and dev_insert_metadata_from_file endpoints that allows authenticated attackers to read arbitrary files by supplying absolute file paths in the file_path parameter. Attackers with…

  • CVE-2026-86995MedSep 8, 2026
    risk 0.21cvss 4.3epss 0.00

    n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node validated the repository parameter for fetch or pull, but setUpstream wrote a branch..remote value into repository configuration without validating it. A later fetch or pull…

  • CVE-2026-82111MedAug 28, 2026
    risk 0.21cvss 4.3epss 0.01

    A vulnerability was detected in iswalle getnote-mcp up to 1.5.0. The affected element is the function fs.readFileSync of the file src/index.ts of the component upload_image. Performing a manipulation of the argument image_path results in path traversal. The attack can be…

  • CVE-2026-78638LowAug 25, 2026
    risk 0.21cvss 3.3epss 0.00

    A flaw has been found in peerigon unzip-crx and unzip-crx-3 up to 0.2.0. This affects the function unzip of the file dist/index.js of the component Archive Extraction. Executing a manipulation of the argument destination can lead to path traversal. The attack can only be…

  • CVE-2026-53584MedAug 20, 2026
    risk 0.21cvss 4.3epss 0.00

    libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 does not reject traversal components in a submodule path loaded from…

  • CVE-2026-76614MedAug 19, 2026
    risk 0.21cvss 4.3epss 0.00

    OpenEMR before 8.3.0 contains a path traversal vulnerability in the EDI archive restore function. The archrestore_sel POST parameter is passed to the archive restore handler without sanitization for path traversal sequences. The handler checks whether the supplied path exists on…

  • CVE-2026-19368LowAug 9, 2026
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was found in PV-Bhat gemsuite-mcp 1.0.0. Affected by this issue is some unknown functionality of the file src/handlers/unified-gemini.ts of the component gemini_search/gemini_reason/gemini_process/gemini_analyze. The manipulation of the argument…

  • CVE-2026-19324LowAug 9, 2026
    risk 0.21cvss 3.3epss 0.00

    A weakness has been identified in HelloGGX shadcn-vue-mcp up to e170e277b94235cde627803277fc8c41103a4d38. Affected by this issue is the function fs.promises.readFile of the file src/server/callback-server.ts. This manipulation of the argument filepath causes path traversal. The…

  • CVE-2026-19059LowAug 6, 2026
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. This affects the function read of the file metagpt/tools/libs/editor.py. This manipulation causes path traversal. The attack needs to be launched locally. The exploit has been publicly disclosed and may be…

  • CVE-2026-19046LowAug 6, 2026
    risk 0.21cvss 3.3epss 0.00

    A security vulnerability has been detected in NocteDefensor LudusMCP up to 1.0.24. The impacted element is an unknown function of the file src/tools/ludusEnvironmentGuidesSearch.ts of the component ludus_environment_guides_search. Such manipulation of the argument guide_name…

  • CVE-2026-55495MedJul 31, 2026
    risk 0.21cvss 4.3epss 0.00

    Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-WOPI-SuggestedTarget to URI.JoinRaw as a path rather than a filename, allowing slash and dot-dot segments to escape the source file directory and create or…

  • CVE-2026-65920MedJul 23, 2026
    risk 0.21cvss 4.3epss 0.00

    Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_files function that allows attackers to read arbitrary files by supplying malicious weight_map values in model index JSON. Attackers can use ../ sequences or…

  • CVE-2025-71394MedJul 18, 2026
    risk 0.21cvss 4.3epss 0.00

    SurrealDB versions before 2.2.2 contain a local file read vulnerability in the DEFINE ANALYZER statement that allows authenticated users to read arbitrary files on the file system. Attackers with root, namespace, or database level privileges can point analyzers to arbitrary file…

  • CVE-2026-46338MedJul 16, 2026
    risk 0.21cvss 4.3epss 0.00

    PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. From 10.0.1 until 10.21.3, pymdownx.snippets uses a string-prefix containment check in SnippetPreprocessor.get_snippet_path() in pymdownx/snippets.py when `restrict_base_path: True`, allowing…

  • CVE-2026-14783MedJul 6, 2026
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was determined in NousResearch hermes-agent 2026.5.29.2. The impacted element is the function skill_view of the file tools/skills_tool.py. Executing a manipulation of the argument Name can lead to path traversal. The attack can be launched remotely. The exploit…