VYPR

CWE-29

Path Traversal: '\..\filename'

VariantIncomplete

Description

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '\..\filename' (leading backslash dot dot) sequences that can resolve to a location that is outside of that directory.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (71)

page 2 of 4
  • CVE-2024-34470HigMay 6, 2024
    risk 0.56cvss 8.6epss 0.07

    An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An Unauthenticated Path Traversal vulnerability exists in the /public/loader.php file. The path parameter does not properly filter whether the file and directory passed are part of the webroot, allowing an…

  • CVE-2024-2356CriFeb 2, 2026
    risk 0.55cvss 9.6epss 0.01

    A Local File Inclusion (LFI) vulnerability exists in the '/reinstall_extension' endpoint of the parisneo/lollms-webui application, specifically within the `name` parameter of the `@router.post("/reinstall_extension")` route. This vulnerability allows attackers to inject a…

  • CVE-2024-3573CriApr 16, 2024
    risk 0.54cvss 9.3epss 0.01

    mlflow/mlflow is vulnerable to Local File Inclusion (LFI) due to improper parsing of URIs, allowing attackers to bypass checks and read arbitrary files on the system. The issue arises from the 'is_local_uri' function's failure to properly handle URIs with empty or 'file'…

  • CVE-2024-10648HigMar 20, 2025
    risk 0.53cvss 8.2epss 0.01

    A path traversal vulnerability exists in the Gradio Audio component of gradio-app/gradio, as of version git 98cbcae. This vulnerability allows an attacker to control the format of the audio file, leading to arbitrary file content deletion. By manipulating the output format, an…

  • CVE-2024-8537CriMar 20, 2025
    risk 0.52cvss 9.1epss 0.01

    A path traversal vulnerability exists in the modelscope/agentscope application, affecting all versions. The vulnerability is present in the /delete-workflow endpoint, allowing an attacker to delete arbitrary files from the filesystem. This issue arises due to improper input…

  • CVE-2024-7774CriOct 29, 2024
    risk 0.52cvss 9.1epss 0.01

    A path traversal vulnerability exists in the `getFullPath` method of langchain-ai/langchainjs version 0.2.5. This vulnerability allows attackers to save files anywhere in the filesystem, overwrite existing text files, read `.txt` files, and delete files. The vulnerability is…

  • CVE-2023-6021HigNov 16, 2023
    risk 0.52cvss 7.5epss 0.37

    LFI in Ray's log API endpoint allows attackers to read any file on the server without authentication. The issue is fixed in version 2.8.1+. Ray maintainers' response can be found here: https://www.anyscale.com/blog/update-on-ray-cves-cve-2023-6019-cve-2023-6020-cve-2023-6021-cve-…

  • CVE-2024-4322HigMay 16, 2024
    risk 0.51cvss 7.5epss 0.31

    A path traversal vulnerability exists in the parisneo/lollms-webui application, specifically within the `/list_personalities` endpoint. By manipulating the `category` parameter, an attacker can traverse the directory structure and list any directory on the system. This issue…

  • CVE-2023-2984HigMay 30, 2023
    risk 0.50cvss 8.8epss 0.01

    Path Traversal: '\..\filename' in GitHub repository pimcore/pimcore prior to 10.5.22.

  • CVE-2025-66608HigFeb 9, 2026
    risk 0.49cvss 7.5epss 0.00

    A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly validate URLs. An attacker could send specially crafted requests to steal files from the web server. The affected products and versions are as follows:…

  • CVE-2024-21542HigDec 10, 2024
    risk 0.49cvss 8.6epss 0.01

    Versions of the package luigi before 3.6.0 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) due to improper destination file path validation in the _extract_packages_archive function.

  • CVE-2024-6394HigSep 30, 2024
    risk 0.49cvss 7.5epss 0.01

    A Local File Inclusion vulnerability exists in parisneo/lollms-webui versions below v9.8. The vulnerability is due to unverified path concatenation in the `serve_js` function in `app.py`, which allows attackers to perform path traversal attacks. This can lead to unauthorized…

  • CVE-2024-2178HigJun 2, 2024
    risk 0.49cvss 7.5epss 0.01

    A path traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'copy_to_custom_personas' endpoint in the 'lollms_personalities_infos.py' file. This vulnerability allows attackers to read arbitrary files by manipulating the 'category' and 'name'…

  • CVE-2023-6909HigDec 18, 2023
    risk 0.49cvss 7.5epss 0.90

    Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.

  • CVE-2023-6038HigNov 16, 2023
    risk 0.49cvss 7.5epss 0.04

    A Local File Inclusion (LFI) vulnerability exists in the h2o-3 REST API, allowing unauthenticated remote attackers to read arbitrary files on the server with the permissions of the user running the h2o-3 instance. This issue affects the default installation and does not require…

  • CVE-2023-6023HigNov 16, 2023
    risk 0.49cvss 7.5epss 0.03

    An attacker can read any file on the filesystem on the server hosting ModelDB through an LFI in the artifact_path URL parameter.

  • CVE-2025-12790HigNov 6, 2025
    risk 0.48cvss 7.4epss 0.00

    A flaw was found in Rubygem MQTT. By default, the package used to not have hostname validation, resulting in possible Man-in-the-Middle (MITM) attack.

  • CVE-2024-21518HigJun 22, 2024
    risk 0.48cvss 7.2epss 0.14

    This affects versions of the package opencart/opencart from 4.0.0.0. A Zip Slip issue was identified via the marketplace installer due to improper sanitization of the target path, allowing files within a malicious archive to traverse the filesystem and be extracted to arbitrary…

  • CVE-2024-6139HigJun 27, 2024
    risk 0.47cvss 7.3epss 0.01

    A path traversal vulnerability exists in the XTTS server of the parisneo/lollms package version v9.6. This vulnerability allows an attacker to write audio files to arbitrary locations on the system and enumerate file paths. The issue arises from improper validation of…

  • CVE-2021-23391HigJun 7, 2021
    risk 0.47cvss 7.3epss 0.00

    This affects all versions of package calipso. It is possible for a malicious module to overwrite files on an arbitrary file system through the module install functionality.