CWE-22

High likelihood

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

9,572 vulnerabilities with CWE-22
CVE-2026-30632 HIGH
knowns 0.11.4 - Path Traversal via Crafted Folder Name in create_doc Tool
CVSS 7.5
CVE-2026-63454 HIGH
Hewlett Packard Enterprise (hpe) Aos-cx < 10.17.1020 - Remote Code Execution
CVSS 7.2
CVE-2026-47425 MEDIUM
Rattler vulnerable to entry-point path traversal in noarch:python install (arbitrary file write)
CVE-2026-47397 HIGH
PraisonAI has an Arbitrary File Write in Python API
CVE-2026-15791 HIGH
Moby BuildKit LLB File Operation - Host /tmp Deletion
CVSS 7.5
CVE-2026-15789 HIGH
Moby BuildKit Local Sources Upload - Path Traversal
CVSS 7.5
CVE-2026-15724 HIGH
Path traversal in Progress ShareFile Storage Zones Controller (SZC)
CVSS 8.7
CVE-2026-64825 CRITICAL
Home Assistant Core < 2026.6.0 Path Traversal File Write via Backup Upload
CVSS 9.3
CVE-2026-64824 HIGH
Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore
CVSS 8.4
CVE-2026-47394 HIGH
PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate
CVE-2026-47121 MEDIUM
Sparkle: Binary delta apply intermediate-symlink traversal in malicious .delta
CVSS 6.1
CVE-2026-13693 MEDIUM
Bit Form < 3.1.0 - Unauthenticated Arbitrary File Read via Path Traversal
CVSS 5.9
CVE-2026-47144 MEDIUM
Shamefile has an arbitrary file read via shamefile.yaml in shame next
CVSS 5.5
CVE-2026-56623 HIGH
Apache MINA SSHD: Path traversal in org.apache.sshd:sshd-git on Windows
CVSS 7.1
CVE-2026-56452 HIGH
Apache MINA SSHD: Path traversal in SCP file reception
CVSS 7.5
CVE-2026-53594 MEDIUM
FreeScout has Arbitrary File Read in App Logs Viewer via Forged Encrypted Path
CVSS 4.9
CVE-2026-60027 HIGH
Joomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1
CVE-2026-58484 HIGH
Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning
CVSS 7.1
CVE-2026-58481 MEDIUM
Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directory
CVSS 6.5
CVE-2026-58414 MEDIUM
Network-AI: EnvironmentManager.backup() follows symlinked directories and copies files outside the environment root into backups
CVSS 5.5
CVE-2026-58413 MEDIUM
EnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment data
CVSS 6.1
CVE-2026-46555 HIGH
WhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary file exfiltration
CVSS 7.7
CVE-2026-32820 HIGH
dataCycle Public Markdown Path Traversal Via /docs/*path
CVSS 7.5
CVE-2026-46671 MEDIUM
Rust OneNote Parser < 1.1.1 - Path Traversal in parse_notebook
CVSS 4.4
CVE-2026-45711 MEDIUM
Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs
CVSS 5.9
Details
Vulnerabilities 9,572
Exploit Likelihood High