VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 55 of 520
  • CVE-2026-76409HigSep 16, 2026
    risk 0.57cvss 8.8epss 0.01

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered…

  • CVE-2026-89084HigSep 16, 2026
    risk 0.57cvss —epss 0.01

    HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the software.

  • CVE-2026-92137HigSep 16, 2026
    risk 0.57cvss 8.8epss 0.01

    Jenkins Robot Framework Plugin 6.2.2 and earlier does not check that the archive directory configured for Robot Framework report files is contained within the build directory on the Jenkins controller, allowing attackers with Item/Configure permission to create or replace…

  • CVE-2026-92355HigSep 16, 2026
    risk 0.57cvss —epss 0.01

    In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a path traversal flaw to overwrite arbitrary files on the server, which in some configurations could lead to remote code execution.

  • CVE-2026-61560CriSep 15, 2026
    risk 0.57cvss 9.8epss 0.01

    `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (`SSE=true`) exposes all MCP tools without any authentication. The `upload_markdown` tool reads arbitrary files from the server's local filesystem via an…

  • CVE-2026-81568HigSep 15, 2026
    risk 0.57cvss —epss 0.00

    Joomla Extension - j2commerce.com - Arbitrary file read via `task=download` in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - `J2StoreModelOrderdownloads::getFilePath()` built the on-disk path to a purchased digital download by concatenating the configured attachment folder…

  • CVE-2026-91934HigSep 15, 2026
    risk 0.57cvss 8.8epss 0.01

    Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite databases, allowing authenticated attackers to write arbitrary files. Attackers can write malicious SQLite databases to system directories or inject files into the…

  • CVE-2026-87791HigSep 15, 2026
    risk 0.57cvss —epss 0.00

    A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia theme. The vulnerability allows an unauthenticated attacker to download arbitrary files accessible by the web server process.

  • CVE-2026-91200HigSep 14, 2026
    risk 0.57cvss 8.8epss 0.00

    DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. Attackers operating a malicious container can stream tar entries with traversal sequences to write arbitrary files on the developer workstation, enabling code…

  • CVE-2026-84889HigSep 10, 2026
    risk 0.57cvss 8.8epss 0.01

    IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.

  • CVE-2026-81554HigSep 10, 2026
    risk 0.57cvss 8.8epss 0.01

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.

  • CVE-2026-81551HigSep 10, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path traversal vulnerability.

  • CVE-2026-67281HigSep 5, 2026
    risk 0.57cvss —epss 0.00

    RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare the allocator so that the file-serving…

  • CVE-2026-84671HigSep 2, 2026
    risk 0.57cvss 8.8epss 0.01

    Jenkins File Parameter Plugin 425.v3fa_801681b_5e and earlier allows writing files to arbitrary locations on the Jenkins controller file system through Stapler data binding, which can lead to remote code execution.

  • CVE-2026-84669HigSep 2, 2026
    risk 0.57cvss 8.8epss 0.00

    A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earlier allows attackers with Item/Read permission on jobs that publish Allure report results to read arbitrary files on the Jenkins controller's file system.

  • CVE-2026-73752HigSep 1, 2026
    risk 0.57cvss 8.8epss 0.00

    An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploitation of this vulnerability allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution.

  • CVE-2026-82954CriAug 31, 2026
    risk 0.57cvss 9.9epss 0.01

    A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts of the component Settings. The manipulation of the argument path results in path traversal. The attack can…

  • CVE-2026-82460CriAug 29, 2026
    risk 0.57cvss 9.8epss 0.01

    Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attackers can use path traversal sequences to read, write, move, or copy files outside the configured…

  • CVE-2026-76639HigAug 27, 2026
    risk 0.57cvss 8.8epss 0.01

    Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execute arbitrary commands as root by chaining three weaknesses: an unauthenticated WebRTC-to-DDS bridge on TCP port 9991, a static…

  • CVE-2026-80104CriAug 25, 2026
    risk 0.57cvss 9.8epss 0.01

    DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py takes file.filename as given and writes the request body to…