CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Improper Limitation of a Pa
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.12, when Deno was run in BYONM mode (nodeModules
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecos
Halo is an open source website building tool. Prior to 2.24.3, a path traversal vulnerability in the backup download end
mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.1, the mise HTTP backend builds its inst
PraisonAI (pip package praisonaiagents) before 1.6.78 automatically loads defaults from a project-local .praisonai/confi
PraisonAI before 4.6.78 contains a path traversal vulnerability in ContextGatherer that fails to validate include paths
PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read f
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthori
A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.backup()` recu
Shamefile is a linter for undocumented linter warnings. Prior to version 0.1.7, a path traversal vulnerability in `shame
Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to verify file deleti
Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overw
Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traver
CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitr
MobSF is a mobile application security testing tool used. Prior to 4.5.1, find_icon_path_zip in mobsf/StaticAnalyzer/vie
Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 7.0
linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfa
nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that
A vulnerability was found in MAA-AI MaaMCP up to 1.1.1.dev6+g2e4a41287. The affected element is the function save_pipeli
A vulnerability was determined in cld378632668 JavaMall up to 994f1e2b019378ec9444cdf3fce2d5b5f72d28f0. Affected is the
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/RecentChan
A vulnerability was determined in ZenTao up to 21.7.8. Affected by this vulnerability is the function delete of the file
A flaw has been found in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07bdd097. T
A vulnerability has been found in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07
A vulnerability has been found in Dromara UJCMS 101.2. This issue affects the function deleteDirectory of the file WebFi
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (ssh_sftpd mo
PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, An unauthenticated path traversal vulnerabil
A vulnerability has been found in SSCMS 4.7.0. The affected element is an unknown function of the file LayerImageControl
Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From
A vulnerability was found in prasathmani TinyFileManager up to 2.6. Affected is an unknown function of the file /fileman
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and
A flaw has been found in rawchen sims up to 004f783b1db5ecdfad81c8fdc3b34171211112de. Affected by this issue is some unk
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validat
A security flaw has been discovered in AstrBotDevs AstrBot 4.23.6. This vulnerability affects unknown code of the file /
A security vulnerability has been detected in jishenghua jshERP up to 3.6. This vulnerability affects the function addAc
Path traversal vulnerability in the SMS app. Impact: Successful exploitation of this vulnerability may affect availabili
A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach uni
The Mattermost Go module github.com/mattermost/mattermost/server/public versions < v0.1.22 fail to validate path paramet
Patool before 4.0.5 contains a path traversal vulnerability in the safe_extract() function in patoolib/programs/py_tarfi
A weakness has been identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 23105f25dadf57b4314fc015a63a7c6e910c
A vulnerability was identified in zhayujie CowAgent up to 2.1.0. The affected element is the function _add_url/_add_pack
The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a
A vulnerability was identified in danpros HTMLy up to 3.1.1. Affected by this issue is the function unlink of the file /
A security flaw has been discovered in danpros HTMLy up to 3.1.1. This affects the function add_content of the file /sys
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started