CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submitted
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who controls or tampers wi
Notepad++ is a free and open-source source code editor. Prior to 8.9.7, Notepad++ validates the backupFilePath attribute
DataEase is an open source data visualization and analysis tool. Versions prior to 2.10.23 have a path traversal vulnera
Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata is used by pkg/plugin/manager.go to construct pat
Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, the legacy statel
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.6.0, the perform-sc
The tarfile module's tar and data extraction filters created directories outside the destination for members whose nam
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 an
Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 0.3.9, the Logto Tunnel npm package
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. P
n8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execution vulnerability in the @n8n/workflow-sdk node-s
A path traversal vulnerability in ATutor allows an authenticated user to access files from other course directories when
ATutor is vulnerable to a Path Traversal vulnerability in ZIP extraction functionality. An attacker with instructor priv
A path traversal vulnerability in ATutor's error log viewer allows an attacker with administrative privileges to access
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Estonian Information Sys
Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, DirectoryPromptRegistry
A path traversal vulnerability existed in the handling of MISP object template names during STIX 2 import and MISP-to-ST
Joomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOtheme Pro 2.3.0-5.0.40 - The Files
Joomla Extension - yootheme.com - Unauthenticated arbitrary directory listing via the Gallery element in Zoo < 4.1.66.
Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, the readFile, p
Terragrunt is a flexible orchestration tool that allows Infrastructure as Code written in OpenTofu or Terraform to scale
Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc's user-SQL validator (`inte
Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise's Raft FSM (`int
Joomla Extension - fabrikar.com - Unauthenticated arbitrary directory listing via onAjax_getFolders in Fabrik < 4.7.2 -
Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2.
RansomLook contains a path traversal vulnerability in the handling of the screen field associated with group posts. The
The extension fails to validate a client-supplied template element key before using it to build file paths for saving an
browse-mcp is a Playwright-based headless-browser MCP server for MCP-capable agents. Prior to 0.8.2, browser_download wr
Velero is an open source tool for backing up, restoring, and migrating Kubernetes cluster resources and persistent volum
Affected versions of Flowintel allow attacker-controlled note content to be processed by Pandoc and XeLaTeX during PDF e
Affected versions of Flowintel allow the LOG_FILE configuration value to be modified through system settings without res
In Eclipse SW360 versions 19.0.0, 19.1.0, 19.2.0, 20.0.0, 20.1.0, if the system is configured to use file system storage
n8n-nodes-sqlite3 is a node for operating a local SQLite database from n8n. Prior to 1.0.0, nodes/SqliteNode/v1/SqliteV1
WhoDB is an open source database management tool. While the application only displays Sqlite3 databases present in the d
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnera
The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent insta
Convoy is a KVM server management panel for hosting businesses. In versions 3.9.0-rc3 to before 4.4.1, there is a direct
ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restr
Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.
A Path Traversal vulnerability in the Allsky WebUI version v2024.12.06_06 allows an unauthenticated remote attacker to a
Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate inp
Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate boa
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in adamskaat Countdown & Cl
Flowise is a drag & drop user interface to build a customized large language model flow. In versions prior to 3.0.8, Wri
A Directory Traversal vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6
The Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Paginatio
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
The Bootstrap Ultimate theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started