VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (9,904)

page 446 of 496
  • CVE-2026-20191HigJul 1, 2026
    risk 0.00cvss 7.5epss 0.01

    A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by…

  • CVE-2026-53906HigJul 1, 2026
    risk 0.00cvss 8.2epss 0.00

    MCO is vulnerable to Path Disclosure and Path Traversal in file handling functionality related to data export and upload. Improper validation of the filename parameter allows writing files to arbitrary locations as well as indirect disclosure of absolute server paths through…

  • CVE-2026-56233HigJun 30, 2026
    risk 0.00cvss 8.3epss 0.00

    Capgo before 12.128.2 contains a path traversal vulnerability in the builder upload proxy that allows authenticated users with build permissions to bypass upload restrictions. Attackers can append traversal sequences to the upload path, which are normalized by the WHATWG URL…

  • CVE-2026-52868HigJun 30, 2026
    risk 0.00cvss 8.2epss 0.00

    An unauthenticated attacker can read worklist records from a directory outside the intended per-AE worklist storage area. In a multi-area deployment, this can cross departmental or clinic data separation.

  • CVE-2026-50003CriJun 30, 2026
    risk 0.00cvss 9.8epss 0.01

    A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside the chosen output directory, using both relative (../) paths and absolute paths.

  • CVE-2026-11595MedJun 30, 2026
    risk 0.00cvss 4.3epss 0.01

    IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information from the administrative console's integrated help system.

  • CVE-2026-58372HigJun 30, 2026
    risk 0.00cvss 8.1epss 0.01

    SeaweedFS before 4.34 contains a path traversal vulnerability in the S3 gateway DeleteMultipleObjectsHandler that allows authenticated S3 principals with write access to a single bucket to delete arbitrary objects in other tenants' buckets by supplying object keys containing ../…

  • CVE-2026-58173MedJun 30, 2026
    risk 0.00cvss 6.5epss 0.00

    Vibe-Trading before 0.1.10 contains a path traversal vulnerability that allows attackers to write files outside the intended memory root directory by supplying a malicious memory_type value containing path traversal sequences through the remember tool. Attackers can manipulate…

  • CVE-2026-58171MedJun 30, 2026
    risk 0.00cvss 4.2epss 0.00

    Vibe-Trading before 0.1.10 constructs the swarm run directory by joining a caller-supplied run identifier onto the runs base directory without validation in run_dir (agent/src/swarm/store.py). A crafted run identifier supplied through the MCP swarm tools causes the application…

  • CVE-2026-58170HigJun 30, 2026
    risk 0.00cvss 8.3epss 0.00

    Vibe-Trading before 0.1.10 builds the proposal file path by joining a caller-supplied proposal identifier onto the broker proposals directory without sanitization (agent/src/live/mandate/commit.py). A proposal identifier containing path traversal sequences causes the application…

  • CVE-2026-58166CriJun 30, 2026
    risk 0.00cvss 9.1epss 0.01

    OpenBMB ChatDev through 2.2.0, fixed in commit 4fd4da6, contains a path traversal vulnerability that allows unauthenticated remote attackers to write or delete arbitrary files by supplying a malicious multipart filename in the file upload endpoint. Attackers can send a crafted…

  • CVE-2026-48314MedJun 30, 2026
    risk 0.00cvss 6.5epss 0.01

    ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to gain limited read and…

  • CVE-2026-48313CriJun 30, 2026
    risk 0.00cvss 9.3epss 0.04

    ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read and limited write access. An attacker could exploit this vulnerability to…

  • CVE-2026-57079MedJun 30, 2026
    risk 0.00cvss 5.3epss 0.00

    Net::BitTorrent versions before 2.1.0 for Perl write files outside the download directory via path traversal in peer-supplied metadata. Net::BitTorrent validates file path components only on the .torrent-file ingest path. The peer and magnet metadata path…

  • CVE-2026-11367MedJun 30, 2026
    risk 0.00cvss 6.5epss 0.01

    The PixMagix – WordPress Image Editor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.7.2 via the move_image_on_server function. This makes it possible for authenticated attackers, with author-level access and above, to write…

  • CVE-2026-8023HigJun 29, 2026
    risk 0.00cvss 7.5epss 0.01

    Zephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STATIC_FS, available when CONFIG_FILE_SYSTEM is enabled) that serves files from a configured root directory. Before this fix, both the HTTP/1 and HTTP/2 front-ends placed…

  • CVE-2026-36848HigJun 29, 2026
    risk 0.00cvss 7.5epss 0.01

    Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traversal in the GVOS H-VUE subsystem.

  • CVE-2026-11720CriJun 29, 2026
    risk 0.00cvss 9.1epss 0.00

    A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstream API requests, the URL builder substitutes user-controlled pathParams into the configured tool path and parses the resulting string as a relative URL. While…

  • CVE-2026-13748MedJun 29, 2026
    risk 0.00cvss 6.3epss 0.00

    Improper restriction of file path resolution in Snowflake CLI versions prior to 3.19 allowed arbitrary local file content to be read and transmitted to Snowflake services. An attacker could exploit this by supplying crafted repository or project content that referenced files…

  • CVE-2026-57331CriJun 29, 2026
    risk 0.00cvss 9.9epss 0.00

    Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.