CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside th
Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An una
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r
Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on.
Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFile
Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extr
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG p
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its datab
h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthentica
A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 2
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to t
Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary
Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied pat
An improper path validation vulnerability in AsyncFuncAI/deepwiki-open through commit 16f35a0 allows unauthenticated rem
DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary f
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A succes
Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding.
DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the uplo
Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping th
The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to path traversal. The us
Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoint
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.5 and earlier, a path
Tina is a headless content management system. Prior to 2.1.8 , the TinaCMS CLI dev server combines a permissive CORS con
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and
The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryp
NuGet Gallery is a package repository that powers nuget.org. A security vulnerability exists in the NuGetGallery backend
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TUBITAK BILGEM Software
An issue in the fileMd5 parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with
Wish is an SSH server with defaults and a collection of middlewares. From version 2.0.0 to before version 2.0.1, the SCP
PraisonAI is a multi-agent teams system. Prior to version 4.6.34, PraisonAI's MCP (Model Context Protocol) server (prais
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rocketgenius Inc. Gravit
A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN),
Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers
Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packages/server/src/api/ro
Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded fil
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorize
excel-mcp-server is a Model Context Protocol server for Excel file manipulation. A path traversal vulnerability exists i
oxyno-zeta/s3-proxy is an aws s3 proxy written in go. Prior to 5.0.0, s3-proxy contains an authentication bypass caused
AdGuard Home, when started with the --glinet flag, contains an authentication bypass vulnerability that allows unauthent
fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining t
Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider
SiYuan is a personal knowledge management system. Prior to 3.5.10, a path traversal vulnerability in the /export endpoin
A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Seq
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m
Pulpy is a lightweight, cross-platform desktop application packager for web apps. Prior to 0.1.1, Pulpy injects a pulpy.
TypeBot is a chatbot builder tool. In versions 3.16.1 and earlier, POST /api/blocks/file-input/v3/generate-upload-url is
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 5,646 CVE records associated with CWE-22 in our database. Of these, 392 are critical severity, 1567 are high severity, and 1153 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started