VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 471 of 520
  • CVE-2026-52868HigJun 30, 2026
    risk 0.00cvss 8.2epss 0.00

    An unauthenticated attacker can read worklist records from a directory outside the intended per-AE worklist storage area. In a multi-area deployment, this can cross departmental or clinic data separation.

  • CVE-2026-50003CriJun 30, 2026
    risk 0.00cvss 9.8epss 0.01

    A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside the chosen output directory, using both relative (../) paths and absolute paths.

  • CVE-2026-11595MedJun 30, 2026
    risk 0.00cvss 4.3epss 0.01

    IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information from the administrative console's integrated help system.

  • CVE-2026-58372HigJun 30, 2026
    risk 0.00cvss 8.1epss 0.01

    SeaweedFS before 4.34 contains a path traversal vulnerability in the S3 gateway DeleteMultipleObjectsHandler that allows authenticated S3 principals with write access to a single bucket to delete arbitrary objects in other tenants' buckets by supplying object keys containing ../…

  • CVE-2026-58173MedJun 30, 2026
    risk 0.00cvss 6.5epss 0.00

    Vibe-Trading before 0.1.10 contains a path traversal vulnerability that allows attackers to write files outside the intended memory root directory by supplying a malicious memory_type value containing path traversal sequences through the remember tool. Attackers can manipulate…

  • CVE-2026-58171MedJun 30, 2026
    risk 0.00cvss 4.2epss 0.00

    Vibe-Trading before 0.1.10 constructs the swarm run directory by joining a caller-supplied run identifier onto the runs base directory without validation in run_dir (agent/src/swarm/store.py). A crafted run identifier supplied through the MCP swarm tools causes the application…

  • CVE-2026-58170HigJun 30, 2026
    risk 0.00cvss 8.3epss 0.01

    Vibe-Trading before 0.1.10 builds the proposal file path by joining a caller-supplied proposal identifier onto the broker proposals directory without sanitization (agent/src/live/mandate/commit.py). A proposal identifier containing path traversal sequences causes the application…

  • CVE-2026-58166CriJun 30, 2026
    risk 0.00cvss 9.1epss 0.01

    OpenBMB ChatDev through 2.2.0, fixed in commit 4fd4da6, contains a path traversal vulnerability that allows unauthenticated remote attackers to write or delete arbitrary files by supplying a malicious multipart filename in the file upload endpoint. Attackers can send a crafted…

  • CVE-2026-57079MedJun 30, 2026
    risk 0.00cvss 5.3epss 0.00

    Net::BitTorrent versions before 2.1.0 for Perl write files outside the download directory via path traversal in peer-supplied metadata. Net::BitTorrent validates file path components only on the .torrent-file ingest path. The peer and magnet metadata path…

  • CVE-2026-11367MedJun 30, 2026
    risk 0.00cvss 6.5epss 0.01

    The PixMagix – WordPress Image Editor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.7.2 via the move_image_on_server function. This makes it possible for authenticated attackers, with author-level access and above, to write…

  • CVE-2026-12243Jun 30, 2026
    risk 0.00cvss —epss 0.01

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-8023HigJun 29, 2026
    risk 0.00cvss 7.5epss 0.01

    Zephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STATIC_FS, available when CONFIG_FILE_SYSTEM is enabled) that serves files from a configured root directory. Before this fix, both the HTTP/1 and HTTP/2 front-ends placed…

  • CVE-2026-36848HigJun 29, 2026
    risk 0.00cvss 7.5epss 0.01

    Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traversal in the GVOS H-VUE subsystem.

  • CVE-2026-13748MedJun 29, 2026
    risk 0.00cvss 6.3epss 0.00

    Improper restriction of file path resolution in Snowflake CLI versions prior to 3.19 allowed arbitrary local file content to be read and transmitted to Snowflake services. An attacker could exploit this by supplying crafted repository or project content that referenced files…

  • CVE-2026-57331CriJun 29, 2026
    risk 0.00cvss 9.9epss 0.01

    Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.

  • CVE-2026-40521HigJun 29, 2026
    risk 0.00cvss 8.8epss 0.01

    FrontAccounting before 2.4.20 contains a path traversal vulnerability in the attachment upload handler that allows authenticated attackers to execute arbitrary code by uploading files with traversal sequences in the unique_name parameter. Attackers can supply path traversal…

  • CVE-2026-57346HigJun 29, 2026
    risk 0.00cvss 7.1epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Epiphyt Embed Privacy allows Path Traversal. This issue affects Embed Privacy: from n/a through 1.12.3.

  • CVE-2026-13509MedJun 28, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability has been found in RAGapp up to 0.1.5. Affected is the function FileHandler.upload_file/FileHandler.remove_file of the file src/ragapp/backend/controllers/files.py of the component Knowledge File Handler. Such manipulation leads to path traversal. The attack can…

  • CVE-2026-49984HigJun 26, 2026
    risk 0.00cvss 7.7epss 0.01

    Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.23, the local internal-storage backend validates user-supplied paths for .. traversal before it converts Windows-style backslashes to forward slashes. An attacker can therefore smuggle a…

  • CVE-2026-45807HigJun 26, 2026
    risk 0.00cvss 7.7epss 0.01

    Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.43 and 1.3.19, several Kestra API endpoints accept a kestra:// URI from the client and pass it through StorageInterface.parentTraversalGuard before reading the underlying file from the local storage…