CWE-23— Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.— MITRE CWE catalog
484 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-23page 10 of 10
- CVE-2026-59149MEDIUMCVSS 6.5EG 6.52026-07-09
Mockoon provides way to design and run mock APIs. Prior to 9.7.0, a FILE response whose filePath embeds request data is confined by getSafeFilePath in packages/commons-server/src/libs/server/server.ts with resolvedPath.startsWith(staticBas…
- CVE-2026-5966HIGHCVSS 8.1EG 8.12026-04-20
ThreatSonar Anti-Ransomware developed by TeamT5 has an Arbitrary File Deletion vulnerability. Authenticated remote attackers with web access can exploit Path Traversal to delete arbitrary files on the system.
- CVE-2026-59792CRITICALCVSS 9.8EG 9.82026-07-10
In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible
- CVE-2026-59832HIGHCVSS 7.7EG 7.72026-07-09
SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /snippets/*filepath route handler serveSnippets in kernel/server/serve.go joins a single-decoded request path with the snippets directory without subpath co…
- CVE-2026-59995MEDIUMCVSS 5.4EG 5.42026-07-08
sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.
- CVE-2026-59996MEDIUMCVSS 5.4EG 5.42026-07-08
scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
- CVE-2026-60093MEDIUMCVSS 5.5EG 5.52026-08-24
Relative path traversal vulnerability in Apache Camel Azure-Storage Datalake component This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-azure-storage-datalake …
- CVE-2026-61343HIGHCVSS 7.2EG 7.22026-07-09
LibreBooking's email template editor save action passes the submitted template name directly into the destination file path, allowing a remote attacker with administrator credentials to write an arbitrary file outside the template director…
- CVE-2026-62837MEDIUMCVSS 6.5EG 6.52026-08-11
Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
- CVE-2026-62843MEDIUMCVSS 6.8EG 6.82026-07-15
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.63.6 to 2.63.16, File Browser's archive builder uses strings.ReplaceAll(nameInArchive, "\", "/"…
- CVE-2026-63043HIGHCVSS 7.5EG 7.52026-08-20
Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from the Agent host filesystem. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pi…
- CVE-2026-63303MEDIUMCVSS 5.1EG 5.12026-07-28
A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fails to normalize dot-dot-slash (../) sequences before resolving and serving the requested file. An authenticated attacke…
- CVE-2026-63490HIGHCVSS 7.5EG 7.52026-08-20
Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handlebars.springmvc.SpringTemplateLoader resolves attacker-influenced Spring MVC view names through Spring ResourceLoader wit…
- CVE-2026-63509CRITICALCVSS 9.9EG 9.92026-08-20
Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
- CVE-2026-6540HIGHCVSS 7.5EG 7.52026-07-30
Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a result, HTTP requests using path-traversal segments, encoded slashes, or repeated slashes ar…
- CVE-2026-65810HIGHCVSS 7.8EG 7.82026-08-11
Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.
- CVE-2026-66881HIGHCVSS 8.1EG 8.12026-08-05
Relative Path Traversal vulnerability in livebook-dev livebook allows an attacker-authored notebook to write a file with attacker-controlled content to an arbitrary path. A .livemd notebook can declare file_entries metadata, each entry ca…
- CVE-2026-66897CRITICALCVSS 9.9EG 9.92026-08-24
A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target…
- CVE-2026-66906CRITICALCVSS 9.1EG 9.12026-08-24
Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-azure-storage-blob compone…
- CVE-2026-66907HIGHCVSS 7.5EG 7.52026-08-24
Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-google-storage consumer downlo…
- CVE-2026-70337HIGHCVSS 8.8EG 8.82026-08-11
Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.
- CVE-2026-72677HIGHCVSS 7.3EG 7.32026-08-13
Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without re…
- CVE-2026-7404HIGHCVSS 7.3EG 7.32026-04-29
A weakness has been identified in getsimpletool mcpo-simple-server up to 0.2.0. Affected is the function delete_shared_prompt of the file src/mcpo_simple_server/services/prompt_manager/base_manager.py. This manipulation of the argument det…
- CVE-2026-77113MEDIUMCVSS 6.7EG 6.72026-08-20
Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary files with the privileges of the executing user via an attacker controlled key names in …
- CVE-2026-78212HIGHCVSS 7.5EG 7.52026-08-24
4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit a Relative Path Traversal flaw to download arbitrary system files.
- CVE-2026-8023HIGHCVSS 7.5EG 7.52026-06-29
Zephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STATIC_FS, available when CONFIG_FILE_SYSTEM is enabled) that serves files from a configured root directory. Before this fix, both th…
- CVE-2026-8073HIGHCVSS 7.5EG 7.52026-05-19
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation and missing capability check in the 'downloadZIP' function in all vers…
- CVE-2026-8100HIGHCVSS 8.6EG 8.62026-06-18
Impact A security issue has been identified in Chef 360 that could allow unauthorized access to protected API endpoints under specific conditions. This issue is due to improper handling of URL-encoded paths during request processing. In …
- CVE-2026-8134HIGHCVSS 7.2EG 7.22026-05-21
Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate field when saving page type composer form layouts. An authenticated rogue administrator with composer form editing …
- CVE-2026-8209MEDIUMCVSS 6.9EG 6.92026-05-09
Gibbon versions before v30.0.01 are affected by a path traversal vulnerability resulting in DOS by attempting extraction of web application PHP files, failed .zip extraction results in deletion of the file and a DOS condition. Successful e…
- CVE-2026-8326CRITICALCVSS 10.0EG 10.02026-05-29
Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitrary files in all directories as root. This leads to RCE. The affected component is the RDP drive redirection. Dependi…
- CVE-2026-8361HIGHCVSS 7.5EG 7.52026-05-27
A path traversal vulnerability exists in WOSDefaultHttpModule.dll when processing a URL path starting with /woshome
- CVE-2026-8387LOWCVSS 2.4EG 2.42026-07-01
A vulnerability in allegroai/clearml versions up to and including 1.16.5 allows for relative path traversal when extracting `.zip` archives using the `ZipFile.extractall()` method in `StorageManager._extract_to_cache()`. This issue arises …
- CVE-2026-8650HIGHCVSS 7.5EG 7.52026-07-08
Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
Map vulnerabilities like CWE-23 to your infrastructure
EchelonGraph correlates every CVE — across CWE-23 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →