VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 82 of 520
  • CVE-2009-4194HigDec 3, 2009
    risk 0.56cvss 8.1epss 0.03

    Directory traversal vulnerability in Golden FTP Server 4.30 Free and Professional, 4.50, and possibly other versions allows remote authenticated users to delete arbitrary files via a .. (dot dot) in the DELE command. NOTE: some of these details are obtained from third party…

  • CVE-2008-5748HigDec 29, 2008
    risk 0.56cvss 8.1epss 0.10

    Directory traversal vulnerability in plugins/spaw2/dialogs/dialog.php in BloofoxCMS 0.3.4 allows remote attackers to read arbitrary files via the (1) lang, (2) theme, and (3) module parameters.

  • CVE-2026-54053CriSep 17, 2026
    risk 0.55cvss 9.6epss 0.01

    Many Notes is a Markdown note-taking web application designed for simplicity. Prior to 0.16.0, the ZIP vault import implemented in app/Actions/ProcessImportedVault.php accepts archive filenames containing parent-directory traversal segments. An authenticated user can write…

  • CVE-2026-81540HigSep 10, 2026
    risk 0.55cvss 8.5epss 0.00

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a path traversal vulnerability.

  • CVE-2026-87030HigSep 9, 2026
    risk 0.55cvss 8.5epss 0.00

    Tanium addressed a path traversal vulnerability in Comply.

  • CVE-2026-87023HigSep 9, 2026
    risk 0.55cvss 8.5epss 0.00

    Tanium addressed a path traversal vulnerability in Comply.

  • CVE-2026-67397HigSep 4, 2026
    risk 0.55cvss —epss 0.00

    Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root.

  • CVE-2026-75604CriSep 1, 2026
    risk 0.55cvss 9.0epss 0.02

    Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently escape backslashes in route segments before…

  • CVE-2026-65092HigAug 25, 2026
    risk 0.55cvss 8.5epss 0.00

    NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7 REST network policy. A successful exploit of this vulnerability might lead to information disclosure and data tampering.

  • CVE-2026-68062HigAug 25, 2026
    risk 0.55cvss 8.5epss 0.01

    SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has…

  • CVE-2026-10053HigAug 23, 2026
    risk 0.55cvss 8.5epss 0.01

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability…

  • CVE-2026-16908HigAug 13, 2026
    risk 0.55cvss 8.5epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to arbitrary objects due to a path traversal vulnerability.

  • CVE-2026-16033HigAug 12, 2026
    risk 0.55cvss 8.5epss 0.00

    A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths from escaping the instance templates directory…

  • CVE-2026-50540CriAug 7, 2026
    risk 0.55cvss 9.6epss 0.00

    Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable to host code execution via an unvalidated configuration path annotation. The…

  • CVE-2025-26240HigJun 17, 2026
    risk 0.55cvss 8.4epss 0.00

    In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server application and the exfiltration of local files.

  • CVE-2026-46703CriJun 10, 2026
    risk 0.55cvss 9.6epss 0.00

    Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version 0.9.0, Boxlite allows users to specify the OCI image used by containers in the sandbox. However, when…

  • CVE-2026-53476CriJun 10, 2026
    risk 0.55cvss 9.6epss 0.00

    A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal vulnerability. By crafting a specially designed gzipped tarball, the attacker can bypass security checks and write arbitrary…

  • CVE-2026-45482HigJun 9, 2026
    risk 0.55cvss 8.4epss 0.00

    Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

  • CVE-2026-49238HigMay 28, 2026
    risk 0.55cvss 8.4epss 0.01

    An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server), which executes with root privileges on the host, contains a path containment bypass vulnerability within its validate_path function in…

  • CVE-2026-9789HigMay 28, 2026
    risk 0.55cvss —epss 0.00

    A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to 3.01.3052. The vulnerability stems from the the PSAdminAgent service, which creates a Named Pipe with a weak Access Control List (ACL). This allows any authenticated local user to…