VYPR

CWE-23

Relative Path Traversal

BaseDraft

Description

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-139 · CAPEC-76

CVEs mapped to this weakness (525)

page 11 of 27
  • CVE-2026-55062HigSep 17, 2026
    risk 0.48cvss —epss 0.00

    uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go concatenates an unvalidated hook filename with the selected hooks directory, allowing parent-directory components to escape that directory. The…

  • CVE-2026-80133HigSep 7, 2026
    risk 0.48cvss 7.4epss 0.01

    Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote…

  • CVE-2026-78254HigSep 7, 2026
    risk 0.48cvss 7.4epss 0.01

    The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it possible to overwrite files of the attacker's choice using the…

  • CVE-2026-44941HigJul 2, 2026
    risk 0.48cvss 8.4epss 0.01

    A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or overwrite files in the target system as root.

  • CVE-2025-52922HigJun 23, 2025
    risk 0.48cvss 7.4epss 0.00

    Innoshop through 0.4.1 allows directory traversal via FileManager API endpoints. An authenticated attacker with access to the admin panel could abuse this to: (1) fully map the filesystem structure via the /api/file_manager/files?base_folder= endpoint, (2) create arbitrary…

  • CVE-2024-43454HigSep 10, 2024
    risk 0.48cvss 7.1epss 0.22

    Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

  • CVE-2021-34605HigMay 11, 2022
    risk 0.48cvss 7.3epss 0.02

    A zip slip vulnerability in XINJE XD/E Series PLC Program Tool up to version v3.5.1 can provide an attacker with arbitrary file write privilege when opening a specially-crafted project file. This vulnerability can be triggered by manually opening an infected project file, or by…

  • CVE-2020-5405MedMar 5, 2020
    risk 0.48cvss 6.5epss 0.69

    Spring Cloud Config, versions 2.2.x prior to 2.2.2, versions 2.1.x prior to 2.1.7, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a…

  • CVE-2026-76424HigSep 16, 2026
    risk 0.47cvss 7.2epss 0.01

    A vulnerability in the REST API of Cisco ISE could allow an authenticated, remote attacker to upload or copy arbitrary files on an affected device. This vulnerability is due to insufficient validation in file operations. An attacker could exploit this vulnerability by…

  • CVE-2026-72677HigAug 13, 2026
    risk 0.47cvss 7.3epss 0.00

    Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences.…

  • CVE-2026-41046HigJun 22, 2026
    risk 0.47cvss 7.3epss 0.00

    A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to use malicious config files for snapper and so cause a denial of service or potentially escalate privileges to root.

  • CVE-2026-7404HigApr 29, 2026
    risk 0.47cvss 7.3epss 0.01

    A weakness has been identified in getsimpletool mcpo-simple-server up to 0.2.0. Affected is the function delete_shared_prompt of the file src/mcpo_simple_server/services/prompt_manager/base_manager.py. This manipulation of the argument detail causes relative path traversal. It…

  • CVE-2026-32725HigMar 31, 2026
    risk 0.47cvss 8.3epss 0.01

    SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass when processing path-based scopes in tokens. The library normalizes the scope path from the token before…

  • CVE-2025-68472HigJan 12, 2026
    risk 0.47cvss 8.1epss 0.20

    MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenticated path traversal in the file upload API lets any caller read arbitrary files from the server filesystem and move them into MindsDB’s storage, exposing…

  • CVE-2025-55752HigOct 27, 2025
    risk 0.47cvss 7.5epss 0.67

    Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query parameters to the …

  • CVE-2025-53779HigAug 12, 2025
    risk 0.47cvss 7.2epss 0.03

    Relative path traversal in Windows Kerberos allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-27791HigApr 15, 2025
    risk 0.47cvss —epss 0.00

    Collabora Online is a collaborative online office suite based on LibreOffice technology. In versions prior to 24.04.12.4, 23.05.19, and 22.05.25, there is a path traversal flaw in handling the CheckFileInfo BaseFileName field returned from WOPI servers. This allows for a file to…

  • CVE-2025-26349HigFeb 12, 2025
    risk 0.47cvss 7.2epss 0.03

    A CWE-23 "Relative Path Traversal" in the file upload mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to overwrite arbitrary files via crafted HTTP requests.

  • CVE-2021-32803HigAug 3, 2021
    risk 0.47cvss 8.2epss 0.08

    The npm package "tar" (aka node-tar) before versions 6.1.2, 5.0.7, 4.4.15, and 3.2.3 has an arbitrary File Creation/Overwrite vulnerability via insufficient symlink protection. `node-tar` aims to guarantee that any file whose location would be modified by a symbolic link is not…

  • CVE-2026-80130HigSep 7, 2026
    risk 0.46cvss 7.1epss 0.00

    Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to remote execution.