VYPR

CWE-41

Improper Resolution of Path Equivalence

BaseIncomplete

Description

The product is vulnerable to file system contents disclosure through path equivalence. Path equivalence involves the use of special characters in file and directory names. The associated manipulations are intended to generate multiple names for the same object.

Path equivalence is usually employed in order to circumvent access controls expressed using an incomplete set of file name or file path representations. This is different from path traversal, wherein the manipulations are performed to generate a name for a different object.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-3

CVEs mapped to this weakness (31)

page 1 of 2
  • CVE-2025-24470HigFeb 11, 2025
    risk 0.56cvss 8.6epss 0.01

    An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.11 may allow a remote unauthenticated attacker to retrieve source code via crafted HTTP requests.

  • CVE-2026-5816HigApr 22, 2026
    risk 0.52cvss 8.0epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.4 and 18.11 before 18.11.1 that could have allowed an unauthenticated user to execute arbitrary JavaScript in a user's browser session due to improper path validation under certain…

  • CVE-2025-43298HigSep 15, 2025
    risk 0.51cvss 7.8epss 0.00

    A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to gain root privileges.

  • CVE-2024-30073HigSep 10, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Security Zone Mapping Security Feature Bypass Vulnerability

  • CVE-2023-36396HigNov 14, 2023
    risk 0.51cvss 7.8epss 0.02

    Windows Compressed Folder Remote Code Execution Vulnerability

  • CVE-2026-23674HigMar 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2024-8765HigMar 20, 2025
    risk 0.48cvss 7.3epss 0.01

    In lunary-ai/lunary, the privilege check mechanism is flawed in version git afc5df4. The system incorrectly identifies certain endpoints as public if the path contains '/auth/' anywhere within it. This allows unauthenticated attackers to access sensitive endpoints by including…

  • CVE-2025-0115MedMar 12, 2025
    risk 0.44cvss epss 0.00

    A vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated admin on the PAN-OS CLI to read arbitrary files. The attacker must have network access to the management interface (web, SSH, console, or telnet) and successfully authenticate to exploit this…

  • CVE-2026-50559HigJun 19, 2026
    risk 0.42cvss 7.5epss 0.00

    Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP path-based authorization policies can be bypassed using encoded semicolons (%3B) to smuggle matrix parameters past…

  • CVE-2024-30036MedMay 14, 2024
    risk 0.42cvss 6.5epss 0.02

    Windows Deployment Services Information Disclosure Vulnerability

  • CVE-2023-46169MedMar 7, 2024
    risk 0.42cvss 6.5epss 0.01

    IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow an authenticated user to arbitrarily delete a file. IBM X-Force ID: 269406.

  • CVE-2026-49401HigJun 23, 2026
    risk 0.40cvss 7.3epss 0.00

    Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.14, Deno's permission system enforces filesystem and execution restrictions by comparing the requested path against the path supplied to --deny-read, --deny-write, --deny-run, or --deny-ffi. On macOS, that…

  • CVE-2024-12217MedMar 20, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the gradio-app/gradio repository, version git 67e4044, allows for path traversal on Windows OS. The implementation of the blocked_path functionality, which is intended to disallow users from reading certain files, is flawed. Specifically, while the application…

  • CVE-2024-45405MedSep 6, 2024
    risk 0.32cvss 6.0epss 0.00

    `gix-path` is a crate of the `gitoxide` project (an implementation of `git` written in Rust) dealing paths and their conversions. Prior to version 0.10.11, `gix-path` runs `git` to find the path of a configuration file associated with the `git` installation, but improperly…

  • CVE-2026-34451MedMar 31, 2026
    risk 0.28cvss 5.4epss 0.00

    Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From version 0.79.0 to before version 0.81.0, the local filesystem memory tool in the Anthropic TypeScript SDK validated model-supplied paths using a string prefix…

  • CVE-2025-54107MedSep 9, 2025
    risk 0.28cvss 4.3epss 0.01

    Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2024-6839MedMar 20, 2025
    risk 0.28cvss 5.3epss 0.01

    corydolphin/flask-cors version 4.0.1 contains an improper regex path matching vulnerability. The plugin prioritizes longer regex patterns over more specific ones when matching paths, which can lead to less restrictive CORS policies being applied to sensitive endpoints. This…

  • CVE-2025-21247MedMar 11, 2025
    risk 0.28cvss 4.3epss 0.03

    Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2025-21332MedJan 14, 2025
    risk 0.28cvss 4.3epss 0.01

    MapUrlToZone Security Feature Bypass Vulnerability

  • CVE-2025-21329MedJan 14, 2025
    risk 0.28cvss 4.3epss 0.02

    MapUrlToZone Security Feature Bypass Vulnerability