CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code
rtapi_app in linuxcnc-uspace in LinuxCNC before 2.9.9 allows privilege escalation. It is installed SUID root and loads s
Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows a
compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the `-o/--
SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode
An issue was discovered in Biztalk360 before 11.5. Because of mishandling of user-provided input in an upload mechanism,
Chamilo LMS is a learning management system. Prior to 1.11.38, there is a path traversal in main/exercise/savescores.php
Vibe-Trading before 0.1.10 builds the proposal file path by joining a caller-supplied proposal identifier onto the broke
Capgo before 12.128.2 contains a path traversal vulnerability in the builder upload proxy that allows authenticated user
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorize
node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink en
An input neutralization vulnerability in the Backup Configuration component of Crafty Controller allows a remote, authen
melange allows users to build apk packages using declarative pipelines. In version 0.11.3 to before 0.40.3, an attacker
calibre is an e-book manager. In 9.1.0 and earlier, a path traversal vulnerability in Calibre's EPUB conversion allows a
A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write f
kaniko is a tool to build container images from a Dockerfile, inside a container or Kubernetes cluster. Starting in vers
Nominas 0.27 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL quer
Zarf is an Airgap Native Packager Manager for Kubernetes. From version 0.54.0 to before version 0.73.1, a path traversal
OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the Feishu media download flow where untr
Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.5, 1.5.5, and 1.6.0-beta.4, t
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high s
i18next-fs-backend is a backend layer for i18next using in Node.js and for Deno to load translations from the filesystem
i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno
jotty·page is a self-hosted app for your checklists and notes. Prior to 1.22.0, an unauthenticated path traversal vulner
Algernon is a small self-contained pure-Go web server. Prior to 1.17.8, when algernon is started with --domain (or --let
F5-TTS through version 1.1.20 contains a path traversal vulnerability in the finetune Gradio handlers that allows unauth
tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal
tmp is a temporary file and directory creator for node.js. In version 0.2.6, the _assertPath guard added to tmp rejects
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
An unauthenticated attacker can read worklist records from a directory outside the intended per-AE worklist storage area
MCO is vulnerable to Path Disclosure and Path Traversal in file handling functionality related to data export and upload
pnpm is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts package names from the env lockfile configDependenc
EverOS is a memory runtime for agents. Prior to 1.0.1, EverOS is vulnerable to path traversal in the POST /api/v1/memory
A path traversal issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS
Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitra
Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5,
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due to improper limitation
GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git repos
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 's nimesis registration service could allow a remote attacker to overwrite
The Mercado Pago Node.js SDK interpolates caller-supplied identifiers into API request paths without percent-encoding th
Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the message's MIME headers with
MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenti
DPanel is an open source server management panel written in Go. Prior to 1.9.2, DPanel has an arbitrary file deletion vu
ConvertXis a self-hosted online file converter. In versions prior to 0.17.0, the `POST /delete` endpoint uses a user-con
An arbitrary file overwrite vulnerability in the file import process of Comic Book Reader v1.0.95 allows attackers to ov
n8n is an open source workflow automation platform. Prior to versions 1.123.12 and 2.4.0, when workflows process uploade
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, a path traversal vulnerability exists in th
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to 1.77.0, the local bl
The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listi
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started