VYPR

CWE-41

Improper Resolution of Path Equivalence

BaseIncomplete

Description

The product is vulnerable to file system contents disclosure through path equivalence. Path equivalence involves the use of special characters in file and directory names. The associated manipulations are intended to generate multiple names for the same object.

Path equivalence is usually employed in order to circumvent access controls expressed using an incomplete set of file name or file path representations. This is different from path traversal, wherein the manipulations are performed to generate a name for a different object.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-3

CVEs mapped to this weakness (31)

page 2 of 2
  • CVE-2025-21328MedJan 14, 2025
    risk 0.28cvss 4.3epss 0.02

    MapUrlToZone Security Feature Bypass Vulnerability

  • CVE-2025-21269MedJan 14, 2025
    risk 0.28cvss 4.3epss 0.05

    Windows HTML Platforms Security Feature Bypass Vulnerability

  • CVE-2025-21268MedJan 14, 2025
    risk 0.28cvss 4.3epss 0.02

    MapUrlToZone Security Feature Bypass Vulnerability

  • CVE-2025-21219MedJan 14, 2025
    risk 0.28cvss 4.3epss 0.03

    MapUrlToZone Security Feature Bypass Vulnerability

  • CVE-2025-21189MedJan 14, 2025
    risk 0.28cvss 4.3epss 0.03

    MapUrlToZone Security Feature Bypass Vulnerability

  • CVE-2026-66064MedJul 28, 2026
    risk 0.27cvss 5.3epss 0.00

    goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/handler.go sendFile handler opened files using a cleaned path but derived the authorization filename from raw req.URL.Path, so a trailing slash could bypass .goshs…

  • CVE-2026-34510MedApr 1, 2026
    risk 0.27cvss 5.3epss 0.00

    OpenClaw before 2026.3.22 contains a path traversal vulnerability in Windows media loaders that accepts remote-host file URLs and UNC-style paths before local-path validation. Attackers can exploit this by providing network-hosted file targets that are treated as local content,…

  • CVE-2026-57441medJun 18, 2026
    risk 0.26cvss epss

    On case-insensitive filesystems (macOS, Windows), PathFilter compiled its deny-list patterns case-sensitively and matched the path verbatim, so names like `.Git/config`, `.GIT/config`, or `.oBsIdIaN/secrets.md` slipped past the `.git`/`.obsidian`/`node_modules` restriction while…

  • CVE-2025-58290LowOct 11, 2025
    risk 0.21cvss 3.3epss 0.00

    Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-50568LowJun 10, 2026
    risk 0.16cvss 3.6epss 0.00

    Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, SanitizeFilePath in pkg/utils/utils.go validated that a path stayed under a safe directory by calling…

  • CVE-2022-0855MedMar 4, 2022
    risk 0.00cvss 6.1epss 0.01

    Improper Resolution of Path Equivalence in GitHub repository microweber-dev/whmcs_plugin prior to 0.0.4.