CWE-23— Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.— MITRE CWE catalog
458 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-23page 9 of 10
- CVE-2026-33494CRITICALCVSS 10.0EG 10.02026-03-26
ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Versions prior to 26.2.0 are vulnerable to an authorization bypass via HTTP path traversal. An …
- CVE-2026-33733HIGHCVSS 7.2EG 7.22026-04-22
EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, the admin template management endpoints accept attacker-controlled `name` and `scope` values and pass them into template path construction with…
- CVE-2026-34026HIGHCVSS 7.1EG 7.12026-06-15
Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a path traversal vulnerability in the documentName parameter of the /safe/selfservice/openselfservicedocument endpoint. The application constructs a file path usin…
- CVE-2026-34926CRITICALCVSS 6.7EG 9.0⚠ KEV2026-05-21
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vuln…
- CVE-2026-39814MEDIUMCVSS 6.7EG 6.72026-04-14
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.1 through 7.4.12, FortiWeb 7.2.7 through 7.2.12, FortiWeb 7.0.10 through 7.0.12 may allow attacker to execute unau…
- CVE-2026-40400HIGHCVSS 8.0EG 8.02026-07-14
Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.
- CVE-2026-41046HIGHCVSS 7.3EG 7.32026-06-22
A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to use malicious config files for snapper and so cause a denial of service or potentially escalate privileges to root.
- CVE-2026-41551CRITICALCVSS 9.1EG 9.12026-05-12
A vulnerability has been identified in ROS# (All versions < V2.2.2). Affected versions contain a path traversal vulnerability because user input is not properly sanitized. This could allow a remote attacker to access arbitrary files on th…
- CVE-2026-41612MEDIUMCVSS 5.5EG 5.52026-05-12
Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally.
- CVE-2026-41948CRITICALCVSS 9.4EG 9.42026-05-18
Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficient URL path sanitization. Attackers can …
- CVE-2026-42085MEDIUMCVSS 4.3EG 4.32026-05-04
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that al…
- CVE-2026-43533HIGHCVSS 8.6EG 8.62026-05-05
OpenClaw before 2026.4.10 contains an arbitrary file read vulnerability in QQBot media tags that allows attackers to reference host-local paths outside the intended media storage boundary. Attackers can craft malicious reply text containin…
- CVE-2026-43616HIGHCVSS 7.1EG 7.12026-05-04
Detect-It-Easy prior to 3.21 contains a path traversal vulnerability that allows attackers to write arbitrary files to the filesystem by crafting malicious archive entries with relative traversal sequences or absolute paths. Attackers can …
- CVE-2026-4415HIGHCVSS 9.8EG 8.12026-03-30
Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. When the pairing feature is enabled, unauthenticated remote attackers can write arbitrary files to any location on the underlying operating system, le…
- CVE-2026-44941HIGHCVSS 8.8EG 8.82026-07-02
A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or overwrite files in the target system as root.
- CVE-2026-44948MEDIUMCVSS 5.3EG 5.32026-06-30
A path traversal vulnerability was found in Fleet's ImageScan subsystem in Rancher Fleet 0.12.0 up to 0.12.16, 0.13.0 up to 0.13.12, 0.14.0 up to 0.14.7 and 0.15.0 up to 0.15.3 could be used to traverse outside of the intended directory, c…
- CVE-2026-45188LOWCVSS 2.4EG 2.42026-06-25
Relative Path Traversal vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.15.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue.
- CVE-2026-47078MEDIUMCVSS 4.8EG 4.82026-07-27
Relative Path Traversal vulnerability in Erlang OTP (stdlib zip module) allows writing files outside the intended extraction directory via a crafted zip archive. zip:unzip/1,2 and zip:extract/1,2 validate entry paths using zip:check_dir_l…
- CVE-2026-47287MEDIUMCVSS 6.5EG 6.52026-06-09
Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.
- CVE-2026-48126HIGHCVSS 8.2EG 8.22026-05-26
Algernon is a small self-contained pure-Go web server. Prior to 1.17.8, when algernon is started with --domain (or --letsencrypt, which silently turns on --domain at engine/flags.go:372), the request handler resolves the served directory b…
- CVE-2026-48569HIGHCVSS 5.5EG 7.12026-06-09
Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
- CVE-2026-48681HIGHCVSS 8.1EG 8.12026-06-04
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.
- CVE-2026-49290HIGHCVSS 7.6EG 7.62026-06-19
Slopsmith is a self-contained web application for browsing, playing, and practicing Rocksmith 2014 Custom DLC (CDLC). Prior to 0.2.9-alpha.5, a path-traversal vulnerability in Slopsmith's archive extractors allows an attacker to write arbi…
- CVE-2026-50016HIGHCVSS 8.8EG 8.82026-06-25
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm allows a transitive dependency alias from registry package metadata to contain path traversal segments. During install, pnpm later uses that alias as a filesystem path when linki…
- CVE-2026-50181HIGHCVSS 7.1EG 7.12026-07-02
Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, Langroid's `ReadFileTool` and `WriteFileTool` appear to treat `curr_dir` as the intended working-directory boundary for file operation…
- CVE-2026-50426MEDIUMCVSS 6.8EG 6.82026-07-14
Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network.
- CVE-2026-50454HIGHCVSS 7.8EG 7.82026-07-14
Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
- CVE-2026-50663HIGHCVSS 8.8EG 8.82026-07-14
Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network.
- CVE-2026-51026MEDIUMCVSS 6.5EG 6.52026-07-20
Directory Traversal vulnerability in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via a crafted request.
- CVE-2026-52813CRITICALCVSS 10.0EG 10.02026-06-23
Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization names containing path traversal sequences (../) are accepted by Gogs, and repositories under them are written to paths following these path traversals. This allo…
- CVE-2026-54066HIGHCVSS 7.5EG 7.52026-06-24
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the patch for CVE-2026-41894 ("Path Traversal via Double URL Encoding") sanitized the /export/ route but the identical root cause remains in the /assets/*path r…
- CVE-2026-5422HIGHCVSS 8.1EG 8.12026-06-02
A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an incorrect root directory boundary check in the _get_os_path() function within jupyter_server/services/contents/fileio.py. The check uses startswith(root) with…
- CVE-2026-54910HIGHCVSS 7.7EG 7.72026-07-20
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-controlled query parameters: `path` and `name`, both of which ar…
- CVE-2026-55474MEDIUMCVSS 6.5EG 6.52026-07-10
Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the route filename parameter into a private upload-directory path without sanitization, allowing an authenticated attacker to t…
- CVE-2026-56196HIGHCVSS 8.8EG 8.82026-07-14
Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.
- CVE-2026-57871HIGHCVSS 7.1EG 7.12026-07-07
Relative path traversal vulnerability in MicroRealEstate file upload functionality allows attackers to potentially overwrite system files. This issue affects MicroRealEstate: through 1.0.0-alpha3.
- CVE-2026-57988HIGHCVSS 7.1EG 7.12026-07-03
Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- CVE-2026-58413MEDIUMCVSS 6.1EG 6.12026-07-20
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.restore(env, backupId)` computes the backup path with `join(envDir, '.backups', backupId)` and only checks that this path exists. It …
- CVE-2026-58481MEDIUMCVSS 6.5EG 6.52026-07-20
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `AgentRuntime` promises scoped file access under a configured sandbox `basePath`, but its path containment checks use raw string prefix tests. A sandbox …
- CVE-2026-58522MEDIUMCVSS 6.8EG 6.82026-07-03
Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
- CVE-2026-59149MEDIUMCVSS 6.5EG 6.52026-07-09
Mockoon provides way to design and run mock APIs. Prior to 9.7.0, a FILE response whose filePath embeds request data is confined by getSafeFilePath in packages/commons-server/src/libs/server/server.ts with resolvedPath.startsWith(staticBas…
- CVE-2026-5966HIGHCVSS 8.1EG 8.12026-04-20
ThreatSonar Anti-Ransomware developed by TeamT5 has an Arbitrary File Deletion vulnerability. Authenticated remote attackers with web access can exploit Path Traversal to delete arbitrary files on the system.
- CVE-2026-59792CRITICALCVSS 9.8EG 9.82026-07-10
In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible
- CVE-2026-59832HIGHCVSS 7.7EG 7.72026-07-09
SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /snippets/*filepath route handler serveSnippets in kernel/server/serve.go joins a single-decoded request path with the snippets directory without subpath co…
- CVE-2026-59995MEDIUMCVSS 5.4EG 5.42026-07-08
sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.
- CVE-2026-59996MEDIUMCVSS 5.4EG 5.42026-07-08
scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
- CVE-2026-61343HIGHCVSS 7.2EG 7.22026-07-09
LibreBooking's email template editor save action passes the submitted template name directly into the destination file path, allowing a remote attacker with administrator credentials to write an arbitrary file outside the template director…
- CVE-2026-62843MEDIUMCVSS 6.8EG 6.82026-07-15
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.63.6 to 2.63.16, File Browser's archive builder uses strings.ReplaceAll(nameInArchive, "\", "/"…
- CVE-2026-7404HIGHCVSS 7.3EG 7.32026-04-29
A weakness has been identified in getsimpletool mcpo-simple-server up to 0.2.0. Affected is the function delete_shared_prompt of the file src/mcpo_simple_server/services/prompt_manager/base_manager.py. This manipulation of the argument det…
- CVE-2026-8023HIGHCVSS 7.5EG 7.52026-06-29
Zephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STATIC_FS, available when CONFIG_FILE_SYSTEM is enabled) that serves files from a configured root directory. Before this fix, both th…
Map vulnerabilities like CWE-23 to your infrastructure
EchelonGraph correlates every CVE — across CWE-23 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →