CWE-23— Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.— MITRE CWE catalog
523 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-23page 7 of 11
- CVE-2025-53779HIGHCVSS 7.2EG 7.22025-08-12
Relative path traversal in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
- CVE-2024-10513HIGHCVSS 7.2EG 7.22025-03-20
A path traversal vulnerability exists in the 'document uploads manager' feature of mintplex-labs/anything-llm, affecting the latest version prior to 1.2.2. This vulnerability allows users with the 'manager' role to access and manipulate th…
- CVE-2025-26349HIGHCVSS 7.2EG 7.22025-02-12
A CWE-23 "Relative Path Traversal" in the file upload mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to overwrite arbitrary files via crafted HTTP requests.
- CVE-2022-1373HIGHCVSS 7.2EG 7.22022-08-17
The “restore configuration” feature of Softing Secure Integration Server V1.22 is vulnerable to a directory traversal vulnerability when processing zip files. An attacker can craft a zip file to load an arbitrary dll and execute code. …
- CVE-2022-1648HIGHCVSS 5.7EG 7.22022-07-26
Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a .php file outside the intended images directory which is restricted to execute the .php file. The impact could lead to…
- CVE-2026-89065HIGHCVSS 7.1EG 7.12026-09-11
Relative path traversal in the generated file manifest cleanup component in projen before 0.101.37 might allow context-dependent attackers to recursively delete files and directories outside the project directory that are writable by the e…
- CVE-2026-81838HIGHCVSS 7.1EG 7.12026-08-27
A relative path traversal issue in the zip extraction functionality in AWS diagram-as-code (awsdac) in versions 0.10 through 0.23 can allow a third party to write arbitrary files to the local filesystem via crafted zip entry names containi…
- CVE-2026-53416HIGHCVSS 7.1EG 7.12026-08-11
Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via local access.
- CVE-2026-57871HIGHCVSS 7.1EG 7.12026-07-07
Relative path traversal vulnerability in MicroRealEstate file upload functionality allows attackers to potentially overwrite system files. This issue affects MicroRealEstate: through 1.0.0-alpha3.
- CVE-2026-57988HIGHCVSS 7.1EG 7.12026-07-03
Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- CVE-2026-50181HIGHCVSS 7.1EG 7.12026-07-02
Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, Langroid's `ReadFileTool` and `WriteFileTool` appear to treat `curr_dir` as the intended working-directory boundary for file operation…
- CVE-2026-34026HIGHCVSS 7.1EG 7.12026-06-15
Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a path traversal vulnerability in the documentName parameter of the /safe/selfservice/openselfservicedocument endpoint. The application constructs a file path usin…
- CVE-2026-43616HIGHCVSS 7.1EG 7.12026-05-04
Detect-It-Easy prior to 3.21 contains a path traversal vulnerability that allows attackers to write arbitrary files to the filesystem by crafting malicious archive entries with relative traversal sequences or absolute paths. Attackers can …
- CVE-2026-22070HIGHCVSS 7.1EG 7.12026-04-30
ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal.
- CVE-2025-24350HIGHCVSS 7.1EG 7.12025-04-30
A vulnerability in the “Certificates and Keys” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to write arbitrary certificates in arbitrary file system paths via a crafted HTTP r…
- CVE-2024-12019HIGHCVSS 7.1EG 7.12025-03-14
The API used to interact with documents in the application contains a flaw that allows an authenticated attacker to read the contents of files on the underlying operating system. An account with ‘read’ and ‘download’ privileges on …
- CVE-2025-23360HIGHCVSS 7.1EG 7.12025-03-11
NVIDIA Nemo Framework contains a vulnerability where a user could cause a relative path traversal issue by arbitrary file write. A successful exploit of this vulnerability may lead to code execution and data tampering.
- CVE-2024-54462HIGHCVSS 7.1EG 7.12025-01-29
The file names constructed within image_picker are missing sanitization checks leaving them vulnerable to malicious document providers. This may result in cases where a user with a malicious document provider installed can select an image …
- CVE-2024-54461HIGHCVSS 7.1EG 7.12025-01-29
The file names constructed within file_selector are missing sanitization checks leaving them vulnerable to malicious document providers. This may result in cases where a user with a malicious document provider installed can select a docume…
- CVE-2024-43454HIGHCVSS 7.1EG 7.12024-09-10
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
- CVE-2023-47613HIGHCVSS 7.1EG 7.12023-11-09
A CWE-23: Relative Path Traversal vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinterion ELS61/81, Telit Cinterion PLS62 that could allow a local, low privileged attacker to escape…
- CVE-2022-33937HIGHCVSS 7.1EG 7.12022-10-12
Dell GeoDrive, Versions 1.0 - 2.2, contain a Path Traversal Vulnerability in the reporting function. A local, low privileged attacker could potentially exploit this vulnerability, to gain unauthorized delete access to the files stored on t…
- CVE-2020-12010HIGHCVSS 7.1EG 7.12020-05-08
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow an authenticated user to use a specially crafted file to delete files outside the application’s contr…
- CVE-2026-48569HIGHCVSS 5.5EG 7.12026-06-09
Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
- CVE-2026-77897HIGHCVSS 7.0EG 7.02026-09-08
Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally.
- CVE-2026-102252MEDIUMCVSS 6.9EG 6.92026-09-29
A path traversal vulnerability (CWE-22) in the embedded VMDK filesystem extractor in Google OSV-SCALIBR versions 0.3.6 through 0.5.0 allows an attacker who controls the scan target to write arbitrary files to the host system. When scanning…
- CVE-2026-8209MEDIUMCVSS 6.9EG 6.92026-05-09
Gibbon versions before v30.0.01 are affected by a path traversal vulnerability resulting in DOS by attempting extraction of web application PHP files, failed .zip extraction results in deletion of the file and a DOS condition. Successful e…
- CVE-2025-59336MEDIUMCVSS 6.9EG 6.92025-09-16
Luanox is a module host for Lua packages. Prior to 0.1.1, a file traversal vulnerability can cause potential denial of service by overwriting Phoenix runtime files. Package names like ../../package are not properly filtered and pass the va…
- CVE-2024-2461MEDIUMCVSS 6.9EG 6.92024-06-11
If exploited an attacker could traverse the file system to access files or directories that would otherwise be inaccessible
- CVE-2026-62843MEDIUMCVSS 6.8EG 6.82026-07-15
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.63.6 to 2.63.16, File Browser's archive builder uses strings.ReplaceAll(nameInArchive, "\", "/"…
- CVE-2026-50426MEDIUMCVSS 6.8EG 6.82026-07-14
Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network.
- CVE-2026-58522MEDIUMCVSS 6.8EG 6.82026-07-03
Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
- CVE-2025-58456MEDIUMCVSS 6.8EG 6.82025-10-23
A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and read arbitra…
- CVE-2024-48892MEDIUMCVSS 6.8EG 6.82025-08-12
A relative path traversal vulnerability [CWE-23] in FortiSOAR 7.6.0, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an authenticated attacker to read arbitrary files via uploading a malicious solution pack.
- CVE-2026-77113MEDIUMCVSS 6.7EG 6.72026-08-20
Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary files with the privileges of the executing user via an attacker controlled key names in …
- CVE-2026-39814MEDIUMCVSS 6.7EG 6.72026-04-14
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.1 through 7.4.12, FortiWeb 7.2.7 through 7.2.12, FortiWeb 7.0.10 through 7.0.12 may allow attacker to execute unau…
- CVE-2024-10019MEDIUMCVSS 6.7EG 6.72025-03-20
A vulnerability in the `start_app_server` function of parisneo/lollms-webui V12 (Strawberry) allows for path traversal and OS command injection. The function does not properly sanitize the `app_name` parameter, enabling an attacker to uplo…
- CVE-2023-29377MEDIUMCVSS 6.6EG 6.62026-09-14
An issue was discovered in Softing OPC UA C++ SDK through 6.20 and Softing Secure Integration Server through 1.22. By using FileType renames, it is possible to bypass limitations on assignment of a directory path to FileDirectory OPC UA ob…
- CVE-2023-33144MEDIUMCVSS 6.6EG 6.62023-06-14
Visual Studio Code Spoofing Vulnerability
- CVE-2026-90466MEDIUMCVSS 6.5EG 6.52026-10-07
Path traversal of 'trusted_jar_paths' in Impala 4.5.2 allows an attacker-controlled JAR to be loaded via a relative path where the prefix matches a path specified in 'trusted_jar_paths'. The startup flag 'trusted_jar_paths' references …
- CVE-2026-106490MEDIUMCVSS 6.5EG 6.52026-10-06
Backstage is an open framework for building developer portals. Prior to 2.2.4, the @backstage/plugin-techdocs-backend package is affected by improper input validation in techdocs static content requests. When using the Azure Blob Storage p…
- CVE-2026-93537MEDIUMCVSS 6.5EG 6.52026-09-28
A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to create or modify a GitRepo, can cause SUSE Rancher Fleet to read files from the filesystem…
- CVE-2026-79728MEDIUMCVSS 6.5EG 6.52026-09-09
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. An unauthenticated attacker with remote access could potentially exploit this …
- CVE-2026-62837MEDIUMCVSS 6.5EG 6.52026-08-11
Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
- CVE-2026-56794MEDIUMCVSS 6.5EG 6.52026-08-07
Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for…
- CVE-2026-18192MEDIUMCVSS 6.5EG 6.52026-07-29
VIN-DS783E-E6 developed by Vacron has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.
- CVE-2026-58481MEDIUMCVSS 6.5EG 6.52026-07-20
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `AgentRuntime` promises scoped file access under a configured sandbox `basePath`, but its path containment checks use raw string prefix tests. A sandbox …
- CVE-2026-51026MEDIUMCVSS 6.5EG 6.52026-07-20
Directory Traversal vulnerability in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via a crafted request.
- CVE-2026-55474MEDIUMCVSS 6.5EG 6.52026-07-10
Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the route filename parameter into a private upload-directory path without sanitization, allowing an authenticated attacker to t…
- CVE-2026-59149MEDIUMCVSS 6.5EG 6.52026-07-09
Mockoon provides way to design and run mock APIs. Prior to 9.7.0, a FILE response whose filePath embeds request data is confined by getSafeFilePath in packages/commons-server/src/libs/server/server.ts with resolvedPath.startsWith(staticBas…
Map vulnerabilities like CWE-23 to your infrastructure
EchelonGraph correlates every CVE — across CWE-23 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →