CWE-22

High likelihood

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

9,576 vulnerabilities with CWE-22
CVE-2026-59194 HIGH
pnpm: patch-remove could delete project-selected files outside the patches directory
CVSS 7.1
CVE-2026-59152 MEDIUM
Arbitrary server-side file read in LangSmith SDK TracingMiddleware
CVSS 5.0
CVE-2026-58203 MEDIUM
NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size
CVSS 5.3
CVE-2026-7185 MEDIUM
T-Systems Archivo - Unauthorized Access to Files in T-Systems Products
CVE-2026-49297 HIGH
Apache Airflow Google provider: Path traversal via GCS object names → local/SFTP filesystem (GCSToSFTPOperator + GCSTimeSpanFileTransformOperator)
CVSS 8.1
CVE-2026-14783 MEDIUM
NousResearch hermes-agent skills_tool.py skill_view path traversal
CVSS 4.3
CVE-2026-59510 HIGH
Authenticated Path Traversal in AIL Framework PDF Object Handling Enables Potential Arbitrary File Read
CVE-2026-14636 MEDIUM
kirilkirkov Ecommerce-CodeIgniter-Bootstrap Vendor Image Manager AddProduct.php do_upload_others_images path traversal
CVSS 5.4
CVE-2026-14635 HIGH
kirilkirkov Ecommerce-CodeIgniter-Bootstrap Vendor Multi-Image Endpoint AddProduct.php path traversal
CVSS 7.3
CVE-2026-14628 MEDIUM
NousResearch hermes-agent Live Webhook Endpoint base.py extract_media path traversal
CVSS 5.3
CVE-2026-28705 MEDIUM
Gitea repository dumps write release assets using unsafe path names
CVSS 5.3
CVE-2026-41124 LOW
Dell PowerProtect Data Domain - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS 2.3
CVE-2026-47896 HIGH
Apache Lucene.Net: Unauthenticated arbitrary file read on the Lucene.Net.Replicator replication server
CVSS 7.5
CVE-2026-47897 HIGH
Apache Lucene.Net: Arbitrary file write from malicious server to Lucene.Net.Replicator client
CVSS 7.5
CVE-2026-9725 CRITICAL
Printcart Web to Print Product Designer for WooCommerce <= 2.5.2 - Unauthenticated Arbitrary File Deletion
CVSS 9.1
CVE-2026-14352 HIGH
AR for WooCommerce <= 8.40 - Unauthenticated Path Traversal to Arbitrary File Read via 'file' Parameter
CVSS 7.5
CVE-2026-14327 HIGH
AR for WordPress <= 8.40 - Unauthenticated Arbitrary File Read via 'file' Parameter
CVSS 7.5
CVE-2026-13054 HIGH
WatchGuard Firebox Arbitrary File Write via Path Traversal in Management Web UI
CVSS 7.2
CVE-2026-58460 HIGH
react-native-receive-sharing-intent Path Traversal via _display_name
CVSS 7.7
CVE-2026-52830 CRITICAL
fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection
CVSS 9.4
CVE-2026-58467 HIGH
Cockpit CMS < 364 - Path Traversal Local File Inclusion via index.php
CVSS 7.5
CVE-2026-7311 HIGH
TinyPNG <= 3.6.13 - Authenticated (Author+) Arbitrary File Deletion via 'convert.path' in 'tiny_compress_images' Post Meta
CVSS 8.1
CVE-2026-55117 HIGH
Ubiquiti INC UniFi Access Application < 4.2.29 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS 8.6
CVE-2026-55111 HIGH
Ubiquiti INC UniFi Protect Floodlight < 1.13.6 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS 7.5
CVE-2026-54406 HIGH
Ubiquiti INC UniFi Network Application < 10.4.57 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS 8.7
Details
Vulnerabilities 9,576
Exploit Likelihood High