CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
A vulnerability was identified in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality
A security flaw has been discovered in geldata gel-mcp 0.1.0. This impacts the function list_rules/fetch_rule of the fil
A vulnerability was found in ggerve coding-standards-mcp. This issue affects the function get_style_guide/get_best_pract
A vulnerability was determined in ghantakiran splunk-mcp-integration up to 0b86b09d5e5adf0433acd43c975951224613a1a6. Imp
A security flaw has been discovered in gyoridavid short-video-maker up to 1.3.4. This affects an unknown part of the fil
novaGallery is a php image gallery. Prior to version 2.1.1, a path traversal vulnerability has been identified in novaGa
A vulnerability was determined in Industrial Application Software IAS Canias ERP 8.03. This vulnerability affects the fu
A security vulnerability has been detected in npitre cramfs-tools up to 2.1. Affected is the function do_directory of th
Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could bypass a proxy route rule by send
Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, pdfengines/merge, pdfengines/split, libreoff
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successf
WWBN AVideo is an open source video platform. In 29.0 and earlier, an unauthenticated remote attacker can read arbitrary
An arbitrary file deletion vulnerability in the /api/delete-temp-license/{file} endpoint of bookcars v8.3 allows unauthe
The unarchive internal module's archive extraction commands perform no code-level validation on extracted file paths, re
YARD is a documentation generation tool for the Ruby programming language. Prior to version 0.9.44, YARD's static cache
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Tra
A vulnerability was detected in antlr ANTLR4 up to 4.13.2. Affected by this issue is the function getImportedVocabFile o
Net::BitTorrent versions before 2.1.0 for Perl write files outside the download directory via path traversal in peer-sup
Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release as
A vulnerability was detected in NousResearch hermes-agent up to 2026.5.16. This impacts the function extract_media of th
pydantic-settings provides settings management using Pydantic. From 2.12.0 until 2.14.2, NestedSecretsSettingsSource rea
The Bulk Order Update for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and i
A vulnerability was detected in TOTOLINK X5000R 9.1.0cu.2415_B20250515/9.1.0cu.2350_B20230313. Affected by this vulnerab
A vulnerability was identified in makafeli n8n-workflow-builder up to 0.11.0. Affected is an unknown function of the fil
A security flaw has been discovered in tugcantopaloglu godot-mcp 2.0.0. Affected by this vulnerability is the function v
A vulnerability has been found in better-auth better-icons up to 1.0.5. This vulnerability affects unknown code of the c
Rejetto HFS 3.0.0 through 3.2.0 allows path traversal through the lang query parameter, permitting a remote unauthentica
A security flaw has been discovered in mastergo-design mastergo-magic-mcp up to 0.2.0. This issue affects the function e
A security vulnerability has been detected in mastergo-design mastergo-magic-mcp up to 0.2.0. The affected element is th
@hapi/inert provides static file and directory handlers for hapi.js. From 4.0.0 to 7.1.0, @hapi/inert serves static file
Traefik versions <= v2.11.51, >= v3.6.0 <= v3.6.22, and >= v3.7.0 <= v3.7.6 contain an authentication bypass via path tr
A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the
Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions.
Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjace
BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that all
A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. Affected by this vulnerability is the function Ex
DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclo
An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a
The Support Genix WordPress plugin before 1.4.48 does not prevent directory traversal in its ticket-attachment download
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract
A weakness has been identified in danpros HTMLy up to 3.1.1. This vulnerability affects unknown code of the file /system
A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDat
A security vulnerability has been detected in ZomboDroid Meme Generator App 4.6830 on Android. This issue affects the fu
A vulnerability was detected in Lspace-io lspace-server up to 79f02fe5aa8970b210a6a05cf097155f8d9ffd71. This issue affec
PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.2
A security flaw has been discovered in Hulupeep mcp-ui-probe up to 0.2.0. Affected is the function get_journey/delete_jo
A vulnerability was detected in aaronsb memory-graph up to 5cfd2382778837b9f6399080956eee670d00452c. Affected by this vu
A flaw has been found in abrinsmead mindpilot-mcp 0.5.0. Affected by this issue is some unknown functionality of the com
A vulnerability has been found in astralisone rive-mcp-server-core up to db1d0cc4cd52589116360428b7504fd0ca748b3e. This
A security flaw has been discovered in azer react-analyzer-mcp up to 335f2a3585f265e2e88352b59b10d3b478d678b0. Affected
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started