CWE-22

High likelihood

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

9,572 vulnerabilities with CWE-22
CVE-2026-46336 HIGH
Manyfold: Authenticated Path Traversal via File Rename
CVSS 7.1
CVE-2026-45576 HIGH
zrok copy writes attacker-controlled WebDAV paths outside the destination root
CVSS 7.5
CVE-2026-45568 CRITICAL
zrok Python ProxyShare can be used as an SSRF proxy through absolute URL paths
CVSS 9.1
CVE-2026-13103 HIGH
Lenovo App Store < 9.0.2930.0514 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS 7.3
CVE-2026-59867 HIGH
Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
CVSS 7.1
CVE-2026-59866 CRITICAL
Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
CVE-2026-59864 CRITICAL
Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions
CVE-2026-53598 HIGH
Prompty: Arbitrary File Read via ${file:path} Reference Expansion
CVSS 7.5
CVE-2026-59863 HIGH
Kiota: Workspace-config poisoning: out-of-repo file write + generation-time SSRF
CVE-2026-52890 HIGH
Wekan: Arbitrary file read and server DoS via attachment versions.original.path
CVSS 7.1
CVE-2026-15921 LOW
nvm path traversal via a malicious mirror's LTS codename writes outside the alias directory
CVSS 3.1
CVE-2026-45533 HIGH
DataEase: Path Traversal Vulnerability
CVE-2026-45419 HIGH
DataEase: Arbitrary File Write Vulnerability
CVE-2026-62947 MEDIUM
OpenWrt: ACL bypass and arbitrary root file read via cgi-io cgi-download
CVSS 4.9
CVE-2026-26032 MEDIUM
Apache Ivy: PackagerResolver path traversal vulnerability
CVSS 5.4
CVE-2026-12997 HIGH
Gravity Forms <= 2.10.4 - Unauthenticated Arbitrary File Read via 'gform_uploaded_files' Parameter
CVSS 7.5
CVE-2026-20297 HIGH
Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise
CVSS 7.2
CVE-2026-20146 MEDIUM
Cisco Identity Services Engine Path Traversal Vulnerability
CVSS 5.5
CVE-2026-62843 MEDIUM
File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)
CVSS 6.8
CVE-2026-60062 MEDIUM
NGINX Agent Vulnerability
CVSS 6.4
CVE-2026-43637 CRITICAL
Cornac < 2.6.0 Path Traversal via _extract_archive() in download.py
CVSS 9.1
CVE-2026-61443 HIGH
PraisonAI before 1.6.78 Remote Code Execution via SkillTools
CVSS 8.1
CVE-2026-56352 MEDIUM
n8n - Arbitrary File Read and Execution via ExecuteWorkflow localFile Parameter
CVSS 6.4
CVE-2026-15751 MEDIUM
mastergo-design mastergo-magic-mcp mcp__getComponentGenerator component-workflow.md execute path traversal
CVSS 5.3
CVE-2026-59733 HIGH
rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories
CVSS 8.8
Details
Vulnerabilities 9,572
Exploit Likelihood High