VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,485)

page 407 of 525
  • CVE-2024-1886LowFeb 26, 2024
    risk 0.20cvss 3.0epss 0.01

    This vulnerability allows remote attackers to traverse the directory on the affected webOS of LG Signage.

  • CVE-2023-6120MedDec 9, 2023
    risk 0.20cvss 4.1epss 0.00

    The Welcart e-Commerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.6 via the upload_certificate_file function. This makes it possible for administrators to upload .pem or .crt files to arbitrary locations on the server.

  • CVE-2021-22151LowNov 22, 2023
    risk 0.20cvss 3.1epss 0.01

    It was discovered that Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a malicious user could arbitrarily traverse the Kibana host to load internal files ending in the .pbf extension.

  • CVE-2017-20152LowDec 30, 2022
    risk 0.20cvss 3.1epss 0.01

    A vulnerability, which was classified as problematic, was found in aerouk imageserve. Affected is an unknown function of the file public/viewer.php of the component File Handler. The manipulation of the argument filelocation leads to path traversal. It is possible to launch the…

  • CVE-2020-1735MedMar 16, 2020
    risk 0.20cvss 4.2epss 0.00

    A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.

  • CVE-2019-3828MedMar 27, 2019
    risk 0.20cvss 4.2epss 0.01

    Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path.

  • CVE-2018-12473LowOct 2, 2018
    risk 0.20cvss 3.1epss 0.02

    A path traversal traversal vulnerability in obs-service-tar_scm of Open Build Service allows remote attackers to cause access files not in the current build. On the server itself this is prevented by confining the worker via KVM. Affected releases are openSUSE Open Build…

  • CVE-2018-16968LowSep 26, 2018
    risk 0.20cvss 3.1epss 0.01

    Citrix ShareFile StorageZones Controller before 5.4.2 allows Directory Traversal.

  • CVE-2016-1000305medJul 31, 2026
    risk 0.19cvss —epss —

    The vulnerability allows remote attackers to read arbitrary files on the server by exploiting improper path validation in the livereload server functionality. This vulnerability is related to the handling of file paths in the livereload server component, which could allow an…

  • CVE-2026-54557MedJun 26, 2026
    risk 0.19cvss 5.5epss 0.00

    mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.1, the mise HTTP backend builds its install symlink destination from the raw resolved version string for non-latest versions. Normal tool install paths use the sanitized version pathname, but the…

  • CVE-2025-65713MedDec 23, 2025
    risk 0.19cvss 4.0epss 0.00

    Home Assistant Core before v2025.8.0 is vulnerable to Directory Traversal. The Downloader integration does not fully validate file paths during concatenation, leaving a path traversal vulnerability.

  • CVE-2023-41040MedAug 30, 2023
    risk 0.19cvss 4.0epss 0.01

    GitPython is a python library used to interact with Git repositories. In order to resolve some git references, GitPython reads files from the `.git` directory, in some places the name of the file being read is provided by the user, GitPython doesn't check if this file is located…

  • CVE-2021-32841MedJan 26, 2022
    risk 0.19cvss 4.0epss 0.01

    SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Starting version 1.3.0 and prior to version 1.3.3, a check was added if the destination file is under destination directory. However, it is not enforced that `destDir` ends with slash. If the `destDir` is not slash…

  • CVE-2025-15693LowSep 5, 2026
    risk 0.18cvss 2.7epss 0.00

    The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its administrative image-browsing features to within the site, allowing high-privilege users, administrators on single-site and sub-site administrators on multisite, to…

  • CVE-2026-82665LowAug 31, 2026
    risk 0.18cvss 3.8epss 0.01

    A vulnerability was detected in yaojingang GEOFlow up to 2.1.0. This vulnerability affects the function unlink of the file app/Http/Controllers/Admin/ImageLibraryController.php of the component Image Library Cleanup. The manipulation of the argument file_path results in path…

  • CVE-2026-76369LowAug 19, 2026
    risk 0.18cvss 2.7epss 0.00

    In Splunk SOAR versions below 8.6.0, a user who holds the OnPrem Broker role could write files outside the intended Automation Broker log directory. The vulnerability is possible because Automation Broker log uploads accept crafted filename input before writing log files. For…

  • CVE-2026-19763LowAug 14, 2026
    risk 0.18cvss 3.8epss 0.01

    A vulnerability was determined in DTStack Taier 1.4.0. Affected by this issue is the function FileUtils.deleteDirectory of the file ClusterController.java of the component Cluster Creation. This manipulation of the argument clusterName causes path traversal. Remote exploitation…

  • CVE-2026-17071LowAug 13, 2026
    risk 0.18cvss 2.7epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform file manipulation due to path traversal.

  • CVE-2026-12211LowJun 15, 2026
    risk 0.18cvss 2.7epss 0.00

    A flaw has been found in Intelbras iNVU 7016 FT 3.004.00IB000.0.T Build 2025-09-26. This impacts an unknown function of the file /RPC2_Loadfile/syslog/ of the component Web Interface. Executing a manipulation can lead to path traversal. The attack can be launched remotely. The…

  • CVE-2024-47267LowMay 27, 2026
    risk 0.18cvss 2.7epss 0.00

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write…