VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 56 of 520
  • CVE-2026-57863HigAug 25, 2026
    risk 0.57cvss 8.8epss 0.01

    Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self-update API that allows authenticated company owners to write arbitrary files outside the intended extraction directory by supplying crafted ZIP archives with ../ sequences to the unzip endpoint.…

  • CVE-2026-66897CriAug 24, 2026
    risk 0.57cvss 9.9epss 0.01

    A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target template paths specified in…

  • CVE-2026-76598HigAug 22, 2026
    risk 0.57cvss —epss 0.00

    Joomla Extension - fabrikar.com - Unauthenticated arbitrary directory listing via onAjax_getFolders in Fabrik < 4.7.2 - The onAjax_getFolders method of the elements model allows arbitrary directory listings.

  • CVE-2026-60084HigAug 22, 2026
    risk 0.57cvss 8.7epss 0.00

    SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability in the /api/search/removeTemplate endpoint that accepts an unvalidated path parameter passed directly to os.RemoveAll. Authenticated admin attackers can supply absolute filesystem paths to recursively…

  • CVE-2026-73040HigAug 20, 2026
    risk 0.57cvss 8.8epss 0.01

    Dockge validates a stack name only on the write path. In backend/stack.ts the allow-list check in validate(), which requires the name to match ^[a-z0-9_-]+$, is reached from save() alone, while the path getter returns path.join(this.server.stacksDir, this.name) and…

  • CVE-2026-64966HigAug 20, 2026
    risk 0.57cvss —epss 0.01

    ATutor is vulnerable to a Path Traversal vulnerability in ZIP extraction functionality. An attacker with instructor privileges can upload and extract a specially crafted ZIP archive, causing files to be written outside the intended extraction directory. This allows an attacker…

  • CVE-2026-77068HigAug 20, 2026
    risk 0.57cvss 8.8epss 0.01

    n8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execution vulnerability in the @n8n/workflow-sdk node-schema loader used for MCP node-schema loading. The loader derives a node's schema module path directly from the attacker-supplied node type string without…

  • CVE-2026-53451CriAug 19, 2026
    risk 0.57cvss 9.8epss 0.01

    Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated save-waterfall-snapshot Socket.IO command passes attacker-controlled snapshotName input from…

  • CVE-2026-52872HigAug 18, 2026
    risk 0.57cvss 8.8epss 0.00

    Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.5.0, the downloadSubtitleFile utility in src/ipc/downloads.js, reached through the run-download IPC channel, accepts a renderer-supplied subtitle url using the file: URI scheme…

  • CVE-2026-45532HigAug 18, 2026
    risk 0.57cvss —epss 0.00

    DataEase is an open source data visualization and analysis tool. Versions prior to 2.10.23 have a path traversal vulnerability. The root cause is that on Windows, the `FILE_SEPARATOR` is `\`, while the server only filters the `/` character during string truncation. The…

  • CVE-2026-74798HigAug 17, 2026
    risk 0.57cvss 8.7epss 0.00

    SiYuan kernel before v3.7.4 contains a path traversal vulnerability in the database_clean MCP tool. The tool performs only an empty-string check on the id parameter before passing it to RemoveUnusedAttributeView (kernel/model/attribute_view.go), which builds a filesystem path…

  • CVE-2026-13622HigAug 12, 2026
    risk 0.57cvss 8.8epss 0.00

    A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc//root/ paths using net.Dial() without symlink protection. These socket paths reside…

  • CVE-2026-13105HigAug 12, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal exploit when importing a configuration.

  • CVE-2026-73034CriAug 11, 2026
    risk 0.57cvss 9.8epss 0.05

    DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the server by injecting directory traversal sequences into the user_id HTTP header of the Python file-upload endpoint. Attackers can…

  • CVE-2026-65768HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.

  • CVE-2026-47661HigAug 7, 2026
    risk 0.57cvss —epss 0.00

    Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's `/$result` endpoint allows a caller who can obtain any valid async export job ID to supply `file` parameter…

  • CVE-2026-47659HigAug 7, 2026
    risk 0.57cvss —epss 0.00

    Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's `/$result` endpoint allows a caller who can obtain any valid async export job ID to supply `file` parameter…

  • CVE-2026-19264CriAug 7, 2026
    risk 0.57cvss 9.8epss 0.01

    Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining it to that directory, and the route requires no…

  • CVE-2026-16263HigAug 7, 2026
    risk 0.57cvss 8.8epss 0.00

    The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-controlled path before using it in a file inclusion, allowing users with a Subscriber account to include and execute arbitrary existing…

  • CVE-2026-49163HigAug 7, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network.