Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)

1,121
CRITICAL
3,545
HIGH
2,893
MEDIUM
199
LOW
8,040 CVEs · Page 32/161
5.3
CVE-2026-7396

A vulnerability was identified in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality

5.3
CVE-2026-7403

A security flaw has been discovered in geldata gel-mcp 0.1.0. This impacts the function list_rules/fetch_rule of the fil

5.3
CVE-2026-7588

A vulnerability was found in ggerve coding-standards-mcp. This issue affects the function get_style_guide/get_best_pract

5.3
CVE-2026-7589

A vulnerability was determined in ghantakiran splunk-mcp-integration up to 0b86b09d5e5adf0433acd43c975951224613a1a6. Imp

5.3
CVE-2026-8115

A security flaw has been discovered in gyoridavid short-video-maker up to 1.3.4. This affects an unknown part of the fil

5.3
CVE-2026-42028

novaGallery is a php image gallery. Prior to version 2.1.1, a path traversal vulnerability has been identified in novaGa

5.3
CVE-2026-8215

A vulnerability was determined in Industrial Application Software IAS Canias ERP 8.03. This vulnerability affects the fu

5.3
CVE-2026-8274

A security vulnerability has been detected in npitre cramfs-tools up to 2.1. Affected is the function do_directory of th

5.3
CVE-2026-44373

Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could bypass a proxy route rule by send

5.3
CVE-2026-42593

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, pdfengines/merge, pdfengines/split, libreoff

5.3
CVE-2026-24208

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successf

5.3
CVE-2026-46337

WWBN AVideo is an open source video platform. In 29.0 and earlier, an unauthenticated remote attacker can read arbitrary

5.3
CVE-2026-36726

An arbitrary file deletion vulnerability in the /api/delete-temp-license/{file} endpoint of bookcars v8.3 allows unauthe

5.3
CVE-2026-12565

The unarchive internal module's archive extraction commands perform no code-level validation on extracted file paths, re

5.3
CVE-2026-49342

YARD is a documentation generation tool for the Ruby programming language. Prior to version 0.9.44, YARD's static cache

5.3
CVE-2026-39899

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Tra

5.3
CVE-2026-13503

A vulnerability was detected in antlr ANTLR4 up to 4.13.2. Affected by this issue is the function getImportedVocabFile o

5.3
CVE-2026-57079

Net::BitTorrent versions before 2.1.0 for Perl write files outside the download directory via path traversal in peer-sup

5.3
CVE-2026-28705

Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release as

5.3
CVE-2026-14628

A vulnerability was detected in NousResearch hermes-agent up to 2026.5.16. This impacts the function extract_media of th

5.3
CVE-2026-58203

pydantic-settings provides settings management using Pydantic. From 2.12.0 until 2.14.2, NestedSecretsSettingsSource rea

5.3
CVE-2026-14500

The Bulk Order Update for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and i

5.3
CVE-2026-15204

A vulnerability was detected in TOTOLINK X5000R 9.1.0cu.2415_B20250515/9.1.0cu.2350_B20230313. Affected by this vulnerab

5.3
CVE-2026-15521

A vulnerability was identified in makafeli n8n-workflow-builder up to 0.11.0. Affected is an unknown function of the fil

5.3
CVE-2026-15522

A security flaw has been discovered in tugcantopaloglu godot-mcp 2.0.0. Affected by this vulnerability is the function v

5.3
CVE-2026-15527

A vulnerability has been found in better-auth better-icons up to 1.0.5. This vulnerability affects unknown code of the c

5.3
CVE-2026-61505

Rejetto HFS 3.0.0 through 3.2.0 allows path traversal through the lang query parameter, permitting a remote unauthentica

5.3
CVE-2026-15749

A security flaw has been discovered in mastergo-design mastergo-magic-mcp up to 0.2.0. This issue affects the function e

5.3
CVE-2026-15751

A security vulnerability has been detected in mastergo-design mastergo-magic-mcp up to 0.2.0. The affected element is th

5.3
CVE-2026-48049

@hapi/inert provides static file and directory handlers for hapi.js. From 4.0.0 to 7.1.0, @hapi/inert serves static file

5.3
CVE-2026-65600

Traefik versions <= v2.11.51, >= v3.6.0 <= v3.6.22, and >= v3.7.0 <= v3.7.6 contain an authentication bypass via path tr

5.3
CVE-2026-16653

A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the

5.3
CVE-2026-57716

Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions.

5.3
CVE-2026-65698

Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjace

5.3
CVE-2026-66004

BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that all

5.3
CVE-2026-17514

A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. Affected by this vulnerability is the function Ex

5.3
CVE-2026-5489

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclo

5.3
CVE-2026-16531

An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a

5.3
CVE-2026-15932

The Support Genix WordPress plugin before 1.4.48 does not prevent directory traversal in its ticket-attachment download

5.3
CVE-2026-69153

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract

5.3
CVE-2026-18646

A weakness has been identified in danpros HTMLy up to 3.1.1. This vulnerability affects unknown code of the file /system

5.3
CVE-2026-18648

A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDat

5.3
CVE-2026-18853

A security vulnerability has been detected in ZomboDroid Meme Generator App 4.6830 on Android. This issue affects the fu

5.3
CVE-2026-19054

A vulnerability was detected in Lspace-io lspace-server up to 79f02fe5aa8970b210a6a05cf097155f8d9ffd71. This issue affec

5.3
CVE-2026-61632

PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.2

5.3
CVE-2026-19270

A security flaw has been discovered in Hulupeep mcp-ui-probe up to 0.2.0. Affected is the function get_journey/delete_jo

5.3
CVE-2026-19285

A vulnerability was detected in aaronsb memory-graph up to 5cfd2382778837b9f6399080956eee670d00452c. Affected by this vu

5.3
CVE-2026-19287

A flaw has been found in abrinsmead mindpilot-mcp 0.5.0. Affected by this issue is some unknown functionality of the com

5.3
CVE-2026-19288

A vulnerability has been found in astralisone rive-mcp-server-core up to db1d0cc4cd52589116360428b7504fd0ca748b3e. This

5.3
CVE-2026-19323

A security flaw has been discovered in azer react-analyzer-mcp up to 335f2a3585f265e2e88352b59b10d3b478d678b0. Affected

Frequently Asked Questions

What is CWE-22?

CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-22?

There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.

How can I protect against CWE-22 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.

Detect CWE-22 Vulnerabilities

CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.

Get Started