VYPR

CWE-36

Absolute Path Traversal

BaseDraft

Description

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as "/abs/path" that can resolve to a location that is outside of that directory.

This allows attackers to traverse the file system to access files or directories that are outside of the restricted directory.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-597

CVEs mapped to this weakness (136)

page 7 of 7
  • CVE-2023-2101MedApr 15, 2023
    risk 0.28cvss 4.3epss 0.01

    A vulnerability, which was classified as problematic, has been found in moxi624 Mogu Blog v2 up to 5.2. This issue affects the function uploadPictureByUrl of the file /mogu-picture/file/uploadPicsByUrl. The manipulation of the argument urlList leads to absolute path traversal.…

  • CVE-2026-44029MedMay 5, 2026
    risk 0.27cvss 5.3epss 0.01

    An issue was discovered in Nix before 2.34.7. Writing to arbitrary files can occur via "nix-prefetch-url --unpack" or "nix store prefetch-file --unpack" directory traversal. The fixed versions are 2.34.7, 2.33.6, 2.32.8, 2.31.5, 2.30.5, 2.29.4, and 2.28.7 (introduced in 2.24.7);

  • CVE-2024-57966MedFeb 3, 2025
    risk 0.26cvss 5.0epss 0.00

    libarchiveplugin.cpp in KDE ark before 24.12.0 can extract to an absolute path from an archive.

  • CVE-2025-8009MedJul 24, 2025
    risk 0.25cvss 4.9epss 0.01

    The Security Ninja – WordPress Security Plugin & Firewall plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.242 via the 'get_file_source' function. This makes it possible for authenticated attackers, with Administrator-level…

  • CVE-2024-1703LowFeb 21, 2024
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2. It has been classified as problematic. This affects the function openfile of the file /adminapi/system/file/openfile. The manipulation leads to absolute path traversal. The exploit has been disclosed to the public and may…

  • CVE-2025-67898MedDec 14, 2025
    risk 0.22cvss 4.5epss 0.00

    MJML through 4.18.0 allows mj-include directory traversal to test file existence and (in the type="css" case) read files. NOTE: this issue exists because of an incomplete fix for CVE-2020-12827.

  • CVE-2023-50955LowFeb 21, 2024
    risk 0.16cvss 2.4epss 0.01

    IBM InfoSphere Information Server 11.7 could allow an authenticated privileged user to obtain the absolute path of the web server installation which could aid in further attacks against the system. IBM X-Force ID: 275777.

  • CVE-2023-1176LowMar 24, 2023
    risk 0.14cvss 3.3epss 0.01

    Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.2.2.

  • CVE-2026-15302MedJul 10, 2026
    risk 0.00cvss 5.3epss 0.01

    The ARMember plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.0.27 via the 'X-FILENAME' HTTP header. This makes it possible for unauthenticated attackers to upload and overwrite certain files (e.g., CSS) to directories outside the…

  • CVE-2026-58300MedJul 3, 2026
    risk 0.00cvss 6.2epss 0.00

    Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

  • CVE-2026-27117MedFeb 24, 2026
    risk 0.00cvss 5.5epss 0.00

    bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4.0.11, a path traversal vulnerability ("Zip Slip") exists in bit7z's archive extraction functionality. The library does not adequately validate file paths…

  • CVE-2026-1020Jan 16, 2026
    risk 0.00cvss epss 0.00

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-1018Jan 16, 2026
    risk 0.00cvss epss 0.01

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2025-53651MedJul 9, 2025
    risk 0.00cvss 6.3epss 0.00

    Jenkins HTML Publisher Plugin 425 and earlier displays log messages that include the absolute paths of files archived during the Publish HTML reports post-build step, exposing information about the Jenkins controller file system in the build log.

  • CVE-2024-56321LowJan 3, 2025
    risk 0.00cvss 3.8epss 0.01

    GoCD is a continuous deliver server. GoCD versions 18.9.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse the backup configuration "post-backup script" feature to potentially execute arbitrary scripts on the hosting server or container as GoCD's user, rather than…

  • CVE-2024-2548HigJun 6, 2024
    risk 0.00cvss 7.5epss 0.01

    A path traversal vulnerability exists in the parisneo/lollms-webui application, specifically within the `lollms_core/lollms/server/endpoints/lollms_binding_files_server.py` and `lollms_core/lollms/security.py` files. Due to inadequate validation of file paths between Windows and…