CWE-22

High likelihood

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

9,125 vulnerabilities with CWE-22
CVE-2026-35487 MEDIUM
text-generation-webui <4.3 load_prompt() - Path Traversal
CVSS 5.3
CVE-2026-35485 HIGH
text-generation-webui <4.3 load_grammar() - Arbitrary File Read
CVSS 7.5
CVE-2026-35484 MEDIUM
text-generation-webui <4.3 load_preset() - Path Traversal
CVSS 5.3
CVE-2026-35483 MEDIUM
text-generation-webui <4.3 load_template() - Path Traversal
CVSS 5.3
CVE-2026-33227 MEDIUM
Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ Web: Improper Limitation of a Pathname to a Restricted Classpath Directory
CVSS 4.3
CVE-2026-35471 CRITICAL
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs
CVSS 9.8
CVE-2026-35454 MEDIUM
Code Extension Marketplace VSIX Extraction - Zip Slip
CVSS 6.5
CVE-2026-35393 CRITICAL
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload
CVSS 9.8
CVE-2026-35392 CRITICAL
goshs <2.0.0-beta.3 PUT Upload - Path Traversal
CVSS 9.8
CVE-2026-35177 MEDIUM
Vim < 9.2.0280 zip.vim - Path Traversal Arbitrary File Overwrite
CVSS 4.1
CVE-2026-35174 CRITICAL
Chyrp Lite <2026.01 Uploads Path - Remote Code Execution
CVSS 9.1
CVE-2026-35167 HIGH
Kedro <1.3.0 Versioned Dataset Loading - Path Traversal
CVSS 7.1
CVE-2026-35050 CRITICAL
text-generation-webui affected by Remote Code Execution (RCE) through Path Traversal at "Session -> Save extention settings to user_data/settings.yaml".
CVSS 9.1
CVE-2026-34783 HIGH
Ferret <2.0.0-alpha.4 IO::FS::WRITE - Arbitrary File Write
CVSS 8.1
CVE-2026-5638 MEDIUM
HerikLyma CPPWebFramework path traversal
CVSS 5.3
CVE-2026-5597 MEDIUM
griptape-ai griptape ComputerTool tool.py path traversal
CVSS 6.3
CVE-2026-5595 MEDIUM
griptape-ai griptape FileManagerTool save_memory_artifacts_to_disk path traversal
CVSS 6.3
CVE-2026-5535 MEDIUM
FedML-AI FedML MQTT Message FileUtils.java path traversal
CVSS 4.3
CVE-2026-3666 HIGH
wpForo Forum <= 2.4.16 - Authenticated (Subscriber+) Arbitrary File Deletion via Post Body
CVSS 8.8
CVE-2026-34607 HIGH
Emlog <=2.6.2 emUnZip() - Path Traversal File Write Code Execution
CVSS 7.2
CVE-2026-34978 MEDIUM
OpenPrinting CUPS: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (and clobbering of job.cache)
CVSS 6.5
CVE-2026-26058 MEDIUM
Zulip: Path Traversal in Import
CVSS 6.1
CVE-2026-22661 HIGH
prompts.chat Path Traversal via Skill File Handling
CVSS 8.1
CVE-2026-28373 CRITICAL
Stackfield Desktop App <1.10.2 - Path Traversal
CVSS 9.6
CVE-2026-35214 HIGH
Budibase: Path traversal in plugin file upload enables arbitrary directory deletion and file write
CVSS 8.7
Details
Vulnerabilities 9,125
Exploit Likelihood High