VYPR

CWE-36

Absolute Path Traversal

BaseDraft

Description

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as "/abs/path" that can resolve to a location that is outside of that directory.

This allows attackers to traverse the file system to access files or directories that are outside of the restricted directory.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-597

CVEs mapped to this weakness (146)

page 7 of 8
  • CVE-2025-53079MedJul 29, 2025
    risk 0.32cvss 4.9epss 0.00

    Absolute Path Traversal in Samsung DMS(Data Management Server) allows authenticated attacker (Administrator) to read sensitive files

  • CVE-2024-10651MedNov 1, 2024
    risk 0.32cvss 4.9epss 0.01

    IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attackers with administrator privileges to exploit this vulnerability to read arbitrary system files.

  • CVE-2026-20834MedJan 13, 2026
    risk 0.30cvss 4.6epss 0.01

    Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.

  • CVE-2026-32175MedMay 12, 2026
    risk 0.28cvss 4.3epss 0.01

    A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited…

  • CVE-2025-15237MedJan 5, 2026
    risk 0.28cvss 4.3epss 0.00

    QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticated remote attackers to read folder names under the specified path by exploiting an Absolute Path Traversal vulnerability.

  • CVE-2025-15236MedJan 5, 2026
    risk 0.28cvss 4.3epss 0.00

    QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticated remote attackers to read folder names under the specified path by exploiting an Absolute Path Traversal vulnerability.

  • CVE-2025-14848MedDec 18, 2025
    risk 0.28cvss 4.3epss 0.01

    Advantech WebAccess/SCADA is vulnerable to absolute directory traversal, which may allow an attacker to determine the existence of arbitrary files.

  • CVE-2023-4172MedAug 5, 2023
    risk 0.28cvss 4.3epss 0.01

    A vulnerability, which was classified as problematic, has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This issue affects some unknown processing of the file \Service\FileHandler.ashx. The manipulation of the argument FileDirectory leads to…

  • CVE-2023-2765MedMay 17, 2023
    risk 0.28cvss 4.3epss 0.02

    A vulnerability has been found in Weaver OA up to 9.5 and classified as problematic. This vulnerability affects unknown code of the file /E-mobile/App/System/File/downfile.php. The manipulation of the argument url leads to absolute path traversal. The attack can be initiated…

  • CVE-2023-2101MedApr 15, 2023
    risk 0.28cvss 4.3epss 0.01

    A vulnerability, which was classified as problematic, has been found in moxi624 Mogu Blog v2 up to 5.2. This issue affects the function uploadPictureByUrl of the file /mogu-picture/file/uploadPicsByUrl. The manipulation of the argument urlList leads to absolute path traversal.…

  • CVE-2026-44029MedMay 5, 2026
    risk 0.27cvss 5.3epss 0.01

    An issue was discovered in Nix before 2.34.7. Writing to arbitrary files can occur via "nix-prefetch-url --unpack" or "nix store prefetch-file --unpack" directory traversal. The fixed versions are 2.34.7, 2.33.6, 2.32.8, 2.31.5, 2.30.5, 2.29.4, and 2.28.7 (introduced in 2.24.7);

  • CVE-2024-57966MedFeb 3, 2025
    risk 0.26cvss 5.0epss 0.00

    libarchiveplugin.cpp in KDE ark before 24.12.0 can extract to an absolute path from an archive.

  • CVE-2025-8009MedJul 24, 2025
    risk 0.25cvss 4.9epss 0.01

    The Security Ninja – WordPress Security Plugin & Firewall plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.242 via the 'get_file_source' function. This makes it possible for authenticated attackers, with Administrator-level…

  • CVE-2025-70820LowSep 13, 2026
    risk 0.23cvss 3.5epss 0.00

    Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder.

  • CVE-2024-1703LowFeb 21, 2024
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2. It has been classified as problematic. This affects the function openfile of the file /adminapi/system/file/openfile. The manipulation leads to absolute path traversal. The exploit has been disclosed to the public and may…

  • CVE-2025-67898MedDec 14, 2025
    risk 0.22cvss 4.5epss 0.00

    MJML through 4.18.0 allows mj-include directory traversal to test file existence and (in the type="css" case) read files. NOTE: this issue exists because of an incomplete fix for CVE-2020-12827.

  • CVE-2023-50955LowFeb 21, 2024
    risk 0.16cvss 2.4epss 0.01

    IBM InfoSphere Information Server 11.7 could allow an authenticated privileged user to obtain the absolute path of the web server installation which could aid in further attacks against the system. IBM X-Force ID: 275777.

  • CVE-2023-1176LowMar 24, 2023
    risk 0.14cvss 3.3epss 0.01

    Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.2.2.

  • CVE-2026-15302MedJul 10, 2026
    risk 0.00cvss 5.3epss 0.01

    The ARMember plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.0.27 via the 'X-FILENAME' HTTP header. This makes it possible for unauthenticated attackers to upload and overwrite certain files (e.g., CSS) to directories outside the…

  • CVE-2026-58300MedJul 3, 2026
    risk 0.00cvss 6.2epss 0.00

    Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.