VYPR

CWE-23

Relative Path Traversal

BaseDraft

Description

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-139 · CAPEC-76

CVEs mapped to this weakness (489)

page 11 of 25
  • CVE-2026-48569HigJun 9, 2026
    risk 0.46cvss 7.1epss 0.00

    Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

  • CVE-2026-5422HigJun 2, 2026
    risk 0.46cvss 8.1epss 0.00

    A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an incorrect root directory boundary check in the _get_os_path() function within jupyter_server/services/contents/fileio.py. The check uses startswith(root) without appending a trailing path separator,…

  • CVE-2026-48126HigMay 26, 2026
    risk 0.46cvss 8.2epss 0.00

    Algernon is a small self-contained pure-Go web server. Prior to 1.17.8, when algernon is started with --domain (or --letsencrypt, which silently turns on --domain at engine/flags.go:372), the request handler resolves the served directory by joining the configured --dir with the…

  • CVE-2026-22070HigApr 30, 2026
    risk 0.46cvss 7.1epss 0.00

    ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal.

  • CVE-2026-39307HigApr 7, 2026
    risk 0.46cvss 8.1epss 0.00

    PraisonAI is a multi-agent teams system. Prior to 1.5.113, The PraisonAI templates installation feature is vulnerable to a "Zip Slip" Arbitrary File Write attack. When downloading and extracting template archives from external sources (e.g., GitHub), the application uses…

  • CVE-2026-27625HigMar 20, 2026
    risk 0.46cvss 8.1epss 0.00

    Stirling-PDF is a locally hosted web application that performs various operations on PDF files. In versions prior to 2.5.2, the /api/v1/convert/markdown/pdf endpoint extracts user-supplied ZIP entries without path checks. Any authenticated user can write files outside the…

  • CVE-2026-29778HigMar 7, 2026
    risk 0.46cvss 7.1epss 0.01

    pyLoad is a free and open-source download manager written in Python. From version 0.5.0b3.dev13 to 0.5.0b3.dev96, the edit_package() function implements insufficient sanitization for the pack_folder parameter. The current protection relies on a single-pass string replacement of…

  • CVE-2025-66626HigDec 9, 2025
    risk 0.46cvss 8.1epss 0.01

    Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Versions 3.6.13 and below and versions 3.7.0 through 3.7.4, contain unsafe untar code that handles symbolic links in archives. Concretely, the computation of a link's…

  • CVE-2025-62156HigOct 14, 2025
    risk 0.46cvss 8.1epss 0.01

    Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Versions prior to 3.6.12 and versions 3.7.0 through 3.7.2 contain a Zip Slip path traversal vulnerability in artifact extraction. During artifact extraction the…

  • CVE-2025-24350HigApr 30, 2025
    risk 0.46cvss 7.1epss 0.00

    A vulnerability in the “Certificates and Keys” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to write arbitrary certificates in arbitrary file system paths via a crafted HTTP request.

  • CVE-2025-2007HigApr 1, 2025
    risk 0.46cvss 8.1epss 0.01

    The Import Export Suite for CSV and XML Datafeed plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteImage() function in all versions up to, and including, 7.19. This makes it possible for authenticated attackers,…

  • CVE-2024-12019HigMar 14, 2025
    risk 0.46cvss epss 0.00

    The API used to interact with documents in the application contains a flaw that allows an authenticated attacker to read the contents of files on the underlying operating system. An account with ‘read’ and ‘download’ privileges on at least one existing document in the…

  • CVE-2025-23360HigMar 11, 2025
    risk 0.46cvss 7.1epss 0.01

    NVIDIA Nemo Framework contains a vulnerability where a user could cause a relative path traversal issue by arbitrary file write. A successful exploit of this vulnerability may lead to code execution and data tampering.

  • CVE-2024-54462HigJan 29, 2025
    risk 0.46cvss 7.1epss 0.00

    The file names constructed within image_picker are missing sanitization checks leaving them vulnerable to malicious document providers. This may result in cases where a user with a malicious document provider installed can select an image file from that provider while using your…

  • CVE-2024-54461HigJan 29, 2025
    risk 0.46cvss 7.1epss 0.00

    The file names constructed within file_selector are missing sanitization checks leaving them vulnerable to malicious document providers. This may result in cases where a user with a malicious document provider installed can select a document file from that provider while using…

  • CVE-2021-27916HigSep 17, 2024
    risk 0.46cvss 8.1epss 0.01

    Prior to the patched version, logged in users of Mautic are vulnerable to Relative Path Traversal/Arbitrary File Deletion. Regardless of the level of access the Mautic user had, they could delete files other than those in the media folders such as system files, libraries or…

  • CVE-2024-32005HigApr 12, 2024
    risk 0.46cvss 8.2epss 0.01

    NiceGUI is an easy-to-use, Python-based UI framework. A local file inclusion is present in the NiceUI leaflet component when requesting resource files under the `/_nicegui/{__version__}/resources/{key}/{path:path}` route. As a result any file on the backend filesystem which the…

  • CVE-2023-30630HigApr 13, 2023
    risk 0.46cvss 7.1epss 0.01

    Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo is plausible. NOTE: Some third parties have indicated the fix in 3.5 does not adequately address the vulnerability. The argument is…

  • CVE-2022-29844MedJan 26, 2023
    risk 0.46cvss 6.7epss 0.36

    A vulnerability in the FTP service of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to read and write arbitrary files. This could lead to a full NAS compromise and would give remote execution capabilities to the attacker.

  • CVE-2022-33937HigOct 12, 2022
    risk 0.46cvss 7.1epss 0.00

    Dell GeoDrive, Versions 1.0 - 2.2, contain a Path Traversal Vulnerability in the reporting function. A local, low privileged attacker could potentially exploit this vulnerability, to gain unauthorized delete access to the files stored on the server filesystem, with the…