CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on Windows hosts
A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism doe
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Include.parse() joins and normalizes use
AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on to
Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the mailpit dump --http <base-url> <ou
The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before reading the
Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix d
SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. D
Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string
SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public web-client partial ZIP
NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen root-derived paths usin
ResourceCacheService.getCacheName() builds the on-disk filename by appending the URI fragment verbatim, without strippin
sigstore framework is a common go library shared across sigstore services and clients. In versions 1.10.3 and below, the
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] vulnerability i
When the director sends a long-running request (e.g. compile_package), the agent's reply JSON is consumed by AgentClient
K3s is a fully conformant production-ready Kubernetes distribution. Prior to 1.35.3+k3s1, 1.34.6+k3s1, v1.33.10+k3s1, a
Unauthenticated Arbitrary File Deletion in ShortPixel Adaptive Images <= 3.11.4 versions.
PraisonAI (praisonaiagents) before 1.6.78 contains a path traversal vulnerability in the FastContext feature (praisonaia
RustDesk versions 1.3.9 through 1.4.9 contain a path traversal vulnerability in the macOS clipboard file-paste code path
SiYuan before v3.8.1 contains a path traversal vulnerability in the asset.upload MCP tool that accepts arbitrary absolut
A vulnerability in the rm utility of uutils coreutils allows the bypass of safeguard mechanisms intended to protect the
Zohocorp ManageEngine ADManager Plus versions below 7230 are vulnerable to Path Traversal in the User Management module
YouPHPTube <= 7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to access arbitrar
pnpm is a package manager. Prior to version 10.28.2, when pnpm processes a package's `directories.bin` field, it uses `p
malcontent discovers supply-chain compromises through. context, differential analysis, and YARA. Starting in version 1.8
Path traversal in Samsung Members prior to Chinese version 15.5.05.4 allows local attackers to overwrite data within Sam
melange allows users to build apk packages using declarative pipelines. From version 0.14.0 to before 0.40.3, an attacke
A path traversal in My Text Editor v1.6.2 allows attackers to cause a Denial of Service (DoS) via writing files to the i
The Post Slides WordPress plugin through 1.0.1 does not validate some shortcode attributes before using them to generate
Outline is a service that allows for collaborative documentation. Prior to 1.4.0, during the JSON import process, the va
A path handling issue was addressed with improved logic. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.
A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 2
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in i
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m
A vulnerability was identified in ZenTao up to 21.7.8. Affected by this issue is the function delete of the file editor/
bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4
eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well
node-tar is a full-featured Tar for Node.js. Prior to version 7.5.11, tar (npm) can be tricked into creating a symlink t
Improper access control in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store
Path traversal in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privileg
A DTrace component, dtprobed, allows arbitrary file creation through crafted USDT provider names.
SeoToaster Ecommerce 3.0.0 contains a local file inclusion vulnerability that allows authenticated attackers to read arb
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0,
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data featur
Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally.
Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.13.0, Microsoft APM conta
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started