CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,572 vulnerabilities with CWE-22
CVE-2026-46336
HIGH
Manyfold: Authenticated Path Traversal via File Rename
CVSS 7.1
CVE-2026-45576
HIGH
zrok copy writes attacker-controlled WebDAV paths outside the destination root
CVSS 7.5
CVE-2026-45568
CRITICAL
zrok Python ProxyShare can be used as an SSRF proxy through absolute URL paths
CVSS 9.1
CVE-2026-13103
HIGH
Lenovo App Store < 9.0.2930.0514 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS 7.3
CVE-2026-59867
HIGH
Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
CVSS 7.1
CVE-2026-59866
CRITICAL
Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
CVE-2026-59864
CRITICAL
Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions
CVE-2026-53598
HIGH
Prompty: Arbitrary File Read via ${file:path} Reference Expansion
CVSS 7.5
CVE-2026-59863
HIGH
Kiota: Workspace-config poisoning: out-of-repo file write + generation-time SSRF
CVE-2026-52890
HIGH
Wekan: Arbitrary file read and server DoS via attachment versions.original.path
CVSS 7.1
CVE-2026-15921
LOW
nvm path traversal via a malicious mirror's LTS codename writes outside the alias directory
CVSS 3.1
CVE-2026-45533
HIGH
DataEase: Path Traversal Vulnerability
CVE-2026-45419
HIGH
DataEase: Arbitrary File Write Vulnerability
CVE-2026-62947
MEDIUM
OpenWrt: ACL bypass and arbitrary root file read via cgi-io cgi-download
CVSS 4.9
CVE-2026-26032
MEDIUM
Apache Ivy: PackagerResolver path traversal vulnerability
CVSS 5.4
CVE-2026-12997
HIGH
Gravity Forms <= 2.10.4 - Unauthenticated Arbitrary File Read via 'gform_uploaded_files' Parameter
CVSS 7.5
CVE-2026-20297
HIGH
Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise
CVSS 7.2
CVE-2026-20146
MEDIUM
Cisco Identity Services Engine Path Traversal Vulnerability
CVSS 5.5
CVE-2026-62843
MEDIUM
File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)
CVSS 6.8
CVE-2026-60062
MEDIUM
NGINX Agent Vulnerability
CVSS 6.4
CVE-2026-43637
CRITICAL
Cornac < 2.6.0 Path Traversal via _extract_archive() in download.py
CVSS 9.1
CVE-2026-61443
HIGH
PraisonAI before 1.6.78 Remote Code Execution via SkillTools
CVSS 8.1
CVE-2026-56352
MEDIUM
n8n - Arbitrary File Read and Execution via ExecuteWorkflow localFile Parameter
CVSS 6.4
CVE-2026-15751
MEDIUM
mastergo-design mastergo-magic-mcp mcp__getComponentGenerator component-workflow.md execute path traversal
CVSS 5.3
CVE-2026-59733
HIGH
rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories
CVSS 8.8
Details
Vulnerabilities
9,572
Exploit Likelihood
High