CWE-23

Relative Path Traversal

Parent: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

461 vulnerabilities with CWE-23
CVE-2026-59995 MEDIUM
Openbsd OpenSSH < 10.4 - Relative Path Traversal
CVSS 4.2
CVE-2026-14476 HIGH
Sssd: sssd: gpo cache path traversal via unsanitized gpcfilesyspath allows kerberos authentication bypass
CVSS 8.0
CVE-2026-57871 HIGH
MicroRealEstate < 1.0.0-alpha3 - Relative Path Traversal
CVE-2026-58522 MEDIUM
Microsoft Edge for Android Information Disclosure Vulnerability
CVSS 6.8
CVE-2026-57988 HIGH
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVSS 7.1
CVE-2026-44941 HIGH
libzypp path traversal via "keyhint" in repomd.xml
CVSS 8.4
CVE-2026-8387 LOW
Relative Path Traversal in allegroai/clearml
CVSS 2.4
CVE-2026-44948 MEDIUM
Path Traversal in Rancher Fleet ImageScan GitRepo Path Handler
CVE-2026-8023 HIGH
Zephyr 4.0.0-4.4.0 HTTP Static FS - Path Traversal File Read
CVSS 7.5
CVE-2026-25707 HIGH
Handcrafted repo metadata may cause arbitrary local files to be overwritten by libzypp
CVSS 8.8
CVE-2026-50016 HIGH
pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement
CVSS 8.8
CVE-2026-45188 LOW
Apache Kvrocks: Replication Fullsync Path Traversal via Unvalidated Filename Handling
CVE-2026-54066 HIGH
SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read)
CVSS 7.5
CVE-2026-52813 CRITICAL
Gogs: Path Traversal in organization name results in RCE through Git hooks
CVSS 10.0
CVE-2026-41046 HIGH
path traversal via `config` parameter in qSnapper
CVSS 7.3
CVE-2026-49290 HIGH
Slopsmith < 0.2.9-alpha.5 - Path Traversal Arbitrary File Write
CVE-2026-10720 MEDIUM
MicroCeph squid/tentacle remote-import API - Path Traversal
CVE-2026-8100 HIGH
Progress Chef Chef360 < 1.7.1 - Relative Path Traversal
CVE-2026-34026 HIGH
Path traversal in Wertheim SafeController Software allows authenticated users to download arbitrary files
CVE-2026-48569 HIGH
Visual Studio Code Security Feature Bypass Vulnerability
CVSS 7.1
CVE-2026-47287 MEDIUM
Visual Studio Code Tampering Vulnerability
CVSS 6.5
CVE-2026-48681 MEDIUM
Openstack Ironic - Relative Path Traversal
CVSS 5.9
CVE-2026-5422 HIGH
Path Traversal in jupyter/jupyter
CVSS 8.1
CVE-2026-10074 MEDIUM
Interinfo|DreamMaker - Arbitrary File Read
CVSS 4.9
CVE-2026-10073 HIGH
Interinfo|DreamMaker - Arbitrary File Read
CVSS 7.5
Details
Vulnerabilities 461