CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,572 vulnerabilities with CWE-22
CVE-2026-59820
MEDIUM
LiteLLM: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS 6.5
CVE-2026-55760
HIGH
handlebars.java FileTemplateLoader Path Traversal
CVSS 7.5
CVE-2026-59924
MEDIUM
Mistune: Arbitrary File Read via Include directive path traversal
CVSS 5.9
CVE-2026-53951
HIGH
Copier: trust-prefix bypass via path traversal runs tasks unprompted
CVE-2026-14967
LOW
Path traversal in github_workflows allows writing artifacts outside output directory
CVSS 3.1
CVE-2026-55874
HIGH
SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read
CVSS 7.7
CVE-2026-55668
MEDIUM
File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope
CVSS 6.3
CVE-2026-56273
MEDIUM
Flowise - Path Traversal in Vector Store basePath Parameter
CVSS 6.5
CVE-2026-53480
LOW
Dell PowerProtect Data Domain - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS 2.7
CVE-2026-22927
HIGH
Omnissa Workspace One® Tunnel For Windows - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS 7.8
CVE-2026-14500
MEDIUM
Bulk Order Update for WooCommerce <= 1.6 - Unauthenticated Arbitrary File Read via 'csv_url' Parameter
CVSS 5.3
CVE-2026-14487
CRITICAL
Simple Coherent Form <= 2.4.13 - Unauthenticated Arbitrary File Deletion via 'id' Parameter
CVSS 9.1
CVE-2026-14244
HIGH
Jssor Slider by jssor.com <= 3.1.24 - Unauthenticated Arbitrary File Read via 'url' Parameter
CVSS 7.5
CVE-2026-55631
HIGH
DataEase: Path Traversal Leading to Arbitrary File Deletion via Font Management
CVE-2026-53481
CRITICAL
Dell PowerProtect Data Domain - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS 9.8
CVE-2026-42200
HIGH
Coolify: PostgreSQL Init Script Path Traversal Leads to Arbitrary File Write and Root RCE
CVSS 8.8
CVE-2026-57571
CRITICAL
Crawl4AI arbitrary file write via download filename path traversal
CVSS 9.6
CVE-2026-14468
HIGH
Path traversal allows arbitrary file read in Terraform Enterprise container
CVSS 7.7
CVE-2026-9181
CRITICAL
Directory Traversal in ArcGIS Server
CVSS 9.8
CVE-2026-59196
HIGH
pnpm: hoisted install imports lockfile alias outside node_modules
CVSS 7.1
CVE-2026-59195
HIGH
pnpm configDependencies - Symlink Path Traversal
CVSS 8.2
CVE-2026-59194
HIGH
pnpm: patch-remove could delete project-selected files outside the patches directory
CVSS 7.1
CVE-2026-59152
MEDIUM
Arbitrary server-side file read in LangSmith SDK TracingMiddleware
CVSS 5.0
CVE-2026-58203
MEDIUM
NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size
CVSS 5.3
CVE-2026-7185
MEDIUM
T-Systems Archivo - Unauthorized Access to Files in T-Systems Products
Details
Vulnerabilities
9,572
Exploit Likelihood
High