CWE-22

High likelihood

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

9,127 vulnerabilities with CWE-22
CVE-2026-24770 CRITICAL
RAGFlow < 0.23.1 - Path Traversal and Remote Code Execution via Malicious ZIP Archive
CVSS 9.8
CVE-2026-24741 HIGH
ConvertX < 0.17.0 - Path Traversal and Arbitrary File Deletion via Delete Endpoint
CVSS 8.1
CVE-2026-23593 HIGH
HPE Aruba Networking Fabric Composer - Info Disclosure
CVSS 7.5
CVE-2026-24801 MEDIUM
Ralim IronOS <2.23-rc3 ecc_dsa.C - Path Traversal
CVE-2026-24686 MEDIUM
go-tuf 2.0.0-2.4.1 - Path Traversal via Repository Name in TAP 4 Multirepo Client
CVSS 4.7
CVE-2026-24486 HIGH
Python-Multipart <0.0.22 - Path Traversal
CVSS 8.6
CVE-2026-24479 CRITICAL
hustoj < 26.01.24 - Path Traversal and Remote Code Execution via ZIP Archive Extraction
CVSS 9.8
CVE-2026-24478 HIGH
AnythingLLM <1.10.0 - Path Traversal
CVSS 7.2
CVE-2026-24123 HIGH
BentoML < 1.4.34 - Path Traversal via bentofile.yaml Configuration Fields
CVSS 7.4
CVE-2026-24131 MEDIUM
pnpm < 10.28.2 - Arbitrary File Permission Modification via directories.bin Path Traversal
CVSS 5.5
CVE-2026-24056 MEDIUM
pnpm < 10.28.2 - Unauthenticated Arbitrary File Read via Symlink in Local/Git Dependencies
CVSS 6.5
CVE-2026-23889 MEDIUM
pnpm < 10.28.1 - Path Traversal via Backslash Directory Separator on Windows
CVSS 6.5
CVE-2026-23888 MEDIUM
pnpm < 10.28.1 - Path Traversal and Arbitrary File Write via Binary Fetcher
CVSS 6.5
CVE-2026-24469 HIGH
C++ HTTP Server <1.0 - Path Traversal
CVSS 7.5
CVE-2026-24137 MEDIUM
sigstore framework <1.10.3 - Buffer Overflow
CVSS 5.8
CVE-2026-20613 HIGH
apple/container < 0.8.0 and apple/containerization < 0.21.0 - Path Traversal via ArchiveReader.extractContents()
CVSS 7.8
CVE-2026-21227 HIGH
Azure Logic Apps - Unauthenticated Path Traversal
CVSS 8.2
CVE-2026-23954 HIGH
Incus <= 6.21.0 - Arbitrary File Read and Write via Template Path Traversal
CVSS 8.7
CVE-2026-24049 HIGH
wheel 0.40.0-0.46.1 - Arbitrary File Permission Modification via Malicious Wheel Archive
CVSS 7.1
CVE-2026-24046 HIGH
Backstage Scaffolder - Symlink-Based Path Traversal and Arbitrary File Read/Write via Template Actions
CVSS 7.1
CVE-2026-23949 HIGH
jaraco.context <6.1.0 - Path Traversal
CVSS 8.6
CVE-2026-22218 MEDIUM
chainlit < 2.9.4 - Authenticated Arbitrary File Read via Project Element Update
CVSS 6.5
CVE-2026-23851 MEDIUM
SiYuan < 3.5.4 - Authenticated Path Traversal via Global Copy Files Endpoint
CVSS 6.5
CVE-2026-23850 HIGH
SiYuan < 3.5.4 - Arbitrary File Read via Markdown HTML Rendering
CVSS 7.5
CVE-2026-23644 HIGH
esm.sh <0.0.0-20260116051925-c62ab83c589e - Path Traversal
CVSS 7.5
Details
Vulnerabilities 9,127
Exploit Likelihood High