CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledg
A flaw has been found in yushine InnoShop up to 0.8.2. Affected by this issue is the function FileManagerController::des
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction w
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to delete arbitrary files due to path
JumpServer is an open source bastion host and an operation and maintenance security audit system. From 4.8.0 until 4.10.
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.3 does not sanitiz
An attacker who can set the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE (the default
A vulnerability was identified in SeaCMS up to 13.6. Affected by this vulnerability is the function unlink of the file /
A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?ac
A vulnerability has been found in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3. This vulnerability af
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an atta
MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.1, a P
Directory traversal vulnerability in InvoicePlane through 1.6.3 allows unauthenticated attackers to read files from the
Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.
JUNG Smart Panel KNX firmware version L1.12.22 and prior contain an unauthenticated path traversal vulnerability in the
A path-traversal vulnerability in the logout functionality of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows
changedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the `/static/<grou
Echo is a Go web framework. In versions 5.0.0 through 5.0.2 on Windows, Echo’s `middleware.Static` using the default fil
NetExec is a network execution tool. Prior to version 1.5.1, the module spider_plus improperly creates the output file a
dbt-common is the shared common utilities for dbt-core and adapter implementations use. Prior to versions 1.34.2 and 1.3
A vulnerability was identified in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). This issue affects som
This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.
Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the plugin file server endpoint uses
Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the filePath parameter accepts path traversal
When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or s
A security flaw has been discovered in Sinaptik AI PandasAI up to 3.0.0. This affects the function is_sql_query_safe of
A vulnerability has been found in elecV2 elecV2P up to 3.8.3. Impacted is the function path.join of the file /store/:key
A vulnerability was found in elecV2 elecV2P up to 3.8.3. The affected element is the function path.join of the file /log
SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode
A vulnerability was detected in HerikLyma CPPWebFramework up to 3.1. This issue affects some unknown processing. Perform
text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticate
text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticate
text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticate
Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, the configuration API endpoint (/api/configuration
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the _safe_extractall() func
Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server’s hand
@hono/node-server allows running the Hono application on Node.js. Prior to 1.19.13, a path handling inconsistency in ser
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path handling
PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he list_files() tool in FileTools validates the directo
A flaw has been found in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects the function dispatch of the file
Rembg is a tool to remove images background. Prior to 2.0.75, a path traversal vulnerability in the rembg HTTP server al
The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by doub
@fastify/static versions 8.0.0 through 9.1.0 allow path traversal when directory listing is enabled via the list option.
A vulnerability was found in 666ghj MiroFish up to 0.1.2. This affects the function get_simulation_posts of the file bac
A vulnerability was found in code-projects Online Lot Reservation System up to 1.0. This affects the function readfile o
A security vulnerability has been detected in OSPG binwalk up to 2.4.3. This vulnerability affects the function read_nul
OpenClaw versions 2026.2.6 through 2026.3.24 contain a path traversal vulnerability in the Feishu extension resolveUploa
A security vulnerability has been detected in Deepractice PromptX up to 2.4.0. The affected element is the function read
A security vulnerability has been detected in ErlichLiu claude-agent-sdk-master up to b185aa7ff0d864581257008077b4010fca
A vulnerability was detected in DV0x creative-ad-agent up to 751b9e5146604dc65049bd0f62dcbdad6212f8a3. Impacted is an un
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started