CWE-29— Path Traversal: '\..\filename'
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '\..\filename' (leading backslash dot dot) sequences that can resolve to a location that is outside of that directory.— MITRE CWE catalog
67 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-29page 2 of 2
- CVE-2024-1561HIGHCVSS 7.5EG 7.52024-04-16
An issue was discovered in gradio-app/gradio, where the `/component_server` endpoint improperly allows the invocation of any method on a `Component` class with attacker-controlled arguments. Specifically, by exploiting the `move_resource_t…
- CVE-2023-6977HIGHCVSS 7.5EG 7.52023-12-20
This vulnerability enables malicious users to read sensitive files on the server.
- CVE-2025-12790HIGHCVSS 7.4EG 7.42025-11-06
A flaw was found in Rubygem MQTT. By default, the package used to not have hostname validation, resulting in possible Man-in-the-Middle (MITM) attack.
- CVE-2024-6139HIGHCVSS 7.3EG 7.32024-06-27
A path traversal vulnerability exists in the XTTS server of the parisneo/lollms package version v9.6. This vulnerability allows an attacker to write audio files to arbitrary locations on the system and enumerate file paths. The issue arise…
- CVE-2021-23391HIGHCVSS 7.3EG 7.32021-06-07
This affects all versions of package calipso. It is possible for a malicious module to overwrite files on an arbitrary file system through the module install functionality.
- CVE-2022-2788HIGHCVSS 3.9EG 7.32022-08-19
Emerson Electric's Proficy Machine Edition Version 9.80 and prior is vulnerable to CWE-29 Path Traversal: '\..\Filename', also known as a ZipSlip attack, through an upload procedure which enables attackers to implant a malicious .BLZ file …
- CVE-2024-8248HIGHCVSS 7.2EG 7.22025-03-20
A vulnerability in the normalizePath function in mintplex-labs/anything-llm version git 296f041 allows for path traversal, leading to arbitrary file read and write in the storage directory. This can result in privilege escalation from mana…
- CVE-2024-13059HIGHCVSS 7.2EG 7.22025-02-10
A vulnerability in mintplex-labs/anything-llm prior to version 1.3.1 allows for path traversal due to improper handling of non-ASCII filenames in the multer library. This vulnerability can lead to arbitrary file write, which can subsequent…
- CVE-2024-21518HIGHCVSS 7.2EG 7.22024-06-22
This affects versions of the package opencart/opencart from 4.0.0.0. A Zip Slip issue was identified via the marketplace installer due to improper sanitization of the target path, allowing files within a malicious archive to traverse the f…
- CVE-2025-50184HIGHCVSS 7.1EG 7.12025-07-26
DbGate is cross-platform database manager. In versions 6.4.3-premium-beta.5 and below, DbGate is vulnerable to a directory traversal flaw. The file parameter is not properly restricted to the intended uploads directory. As a result, the en…
- CVE-2024-51534HIGHCVSS 7.1EG 7.12025-02-01
Dell PowerProtect DD versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.20 contain a path traversal vulnerability. A local low privileged could potentially exploit this vulnerability to gain unauthorized overwrite of OS files stored on …
- CVE-2025-50185HIGHCVSS 7.0EG 7.02025-07-26
DbGate is cross-platform database manager. In versions 6.6.0 and below, DbGate allows unauthorized file access due to insufficient validation of file paths and types. A user with application-level access can retrieve data from arbitrary fi…
- CVE-2026-10732MEDIUMCVSS 6.4EG 6.42026-06-05
All versions of the package decompress are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) when extracting a ZIP archive containing two entries with the same path - the first being a symlink to an arbitrary target and …
- CVE-2024-8982MEDIUMCVSS 6.2EG 6.22025-03-20
A Local File Inclusion (LFI) vulnerability in OpenLLM version 0.6.10 allows attackers to include files from the local server through the web application. This flaw could expose internal server files and potentially sensitive information su…
- CVE-2025-58291MEDIUMCVSS 5.5EG 5.52025-10-11
Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.
- CVE-2023-0316MEDIUMCVSS 5.5EG 5.52023-01-16
Path Traversal: '\..\filename' in GitHub repository froxlor/froxlor prior to 2.0.0.
- CVE-2024-4841MEDIUMCVSS 3.3EG 4.02024-06-23
A Path Traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'add_reference_to_local_mode' function due to the lack of input sanitization. This vulnerability affects versions v9.6 to the latest. By exploiting…
Map vulnerabilities like CWE-29 to your infrastructure
EchelonGraph correlates every CVE — across CWE-29 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →