CWE-22
CVEs classified under CWE-22, newest first.
1061 CVEsRSS
CVE-2026-53584Medium· 4.3libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 does not reject traversal compon…
CVE-2026-69400Critical· 9.6Azure Logic Apps Elevation of Privilege Vulnerability
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-61625Medium· 6.8VictoriaMetrics is a scalable solution for monitoring and managing time series data
VictoriaMetrics is a scalable solution for monitoring and managing time series data. Prior to 1.122.25, 1.136.12, and 1.146.0, vmrestore does not validate backup part path components before using lib/backup/actions/restore.go and lib/bac…
CVE-2026-63490High· 7.5Handlebars.java provides logic-less and semantic Mustache templates with Java
Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handlebars.springmvc.SpringTemplateLoader resolves attacker-influenced Spring MVC view names through Spring ResourceLoader w…
CVE-2026-71492Medium· 6.5Banks generates meaningful LLM prompts using a simple template language
Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, DirectoryPromptRegistry.set() in src/banks/registries/directory.py interpolates attacker-controlled Prompt.name and Prompt.version values in…
GHSA-2223-f22x-24cqMedium· 4.9Winter: Local File Inclusion through =include directives in JavaScript asset compilation
Winter: Local File Inclusion through =include directives in JavaScript asset compilation
CVE-2026-49244Medium· 5.9SFTPGo is an open source, event-driven file transfer solution
SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public web-client partial ZIP download endpoint for a browsable share validates client-supplied files entries with a raw byte-prefix comparison ra…
CVE-2026-76832High· 8.8Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that allows attackers to read, write, or execute arbitrary files by supplying parent-directory traversal sequences in the file_name argument pas…
Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that allows attackers to read, write, or execute arbitrary files by supplying parent-directory traversal sequences in the file_name argument pas…
CVE-2026-53452Medium· 5.3Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding
Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated configure-sdr Socket.IO command accepts a recordingPath for the sigmf-p…
CVE-2026-53451Critical· 9.8Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding
Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated save-waterfall-snapshot Socket.IO command passes attacker-controlled sn…
CVE-2026-75593High· 7.2BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.2, a custom client can produce such an upload request to the BuildKit daemon that files can escape from …
CVE-2026-48024Critical· 9.1Wazuh is a free and open source platform used for threat prevention, detection, and response
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta3, cluster.unmerge_info() in framework/wazuh/core/cluster/cluster.py constructs paths from peer-controlle…
CVE-2026-76614Medium· 4.3OpenEMR before 8.3.0 contains a path traversal vulnerability in the EDI archive restore function
OpenEMR before 8.3.0 contains a path traversal vulnerability in the EDI archive restore function. The archrestore_sel POST parameter is passed to the archive restore handler without sanitization for path traversal sequences. The handler …
CVE-2026-46343High· 7.2Wazuh is a free and open source platform used for threat prevention, detection, and response
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, WazuhCommon.end_receiving_file() in framework/wazuh/core/cluster/common.py allows a cluster-authentica…
CVE-2026-44829High· 8.8Gotenberg is a Docker-powered stateless API for PDF files
Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, filename handling in pkg/modules/api/context.go uses filepath.Base on Linux, which does not treat backslashes as path separators, so a multipart filename c…
GHSA-3vrx-526r-64rmHigh· 8.2Duplicate Advisory: GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython
Duplicate Advisory: GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython
CVE-2026-62680High· 7.1Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.22.0, Orval resolves remote and local external $ref values without an allowlist or confinement to the input directory. P…
CVE-2026-76222High· 8.2gitpython: GitPython: Arbitrary file creation via path traversal in .gitmodules submodule names (CVE-2026-76222)
A flaw was found in GitPython where it fails to properly validate submodule names within .gitmodules files. A remote attacker could craft a malicious Git repository containing specially formed submodule names with directory traversal seque…
CVE-2026-63188HighLogto is the modern, open-source auth infrastructure for SaaS and AI apps
Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 0.3.9, the Logto Tunnel npm package enabled createStaticFileProxy from packages/tunnel/src/commands/tunnel/index.ts and passed request.url from static as…
GHSA-cc2g-gq8c-r332High· 7.5grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools
grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools
GHSA-j4r7-8ph4-43g3High· 7.5faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
GHSA-rr55-jp92-8wp2High· 7.5claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
CVE-2026-53951HighCopier has a trust-prefix bypass via path traversal that runs tasks unprompted
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
CVE-2026-49253High· 7.1electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.11.11, electerm uses remote-supplied filenames directly with path.join() while receiving Zmodem and Trzsz transfers. In src/app/server/z…
CVE-2026-45532NoneDataEase is an open source data visualization and analysis tool
DataEase is an open source data visualization and analysis tool. Versions prior to 2.10.23 have a path traversal vulnerability. The root cause is that on Windows, the `FILE_SEPARATOR` is `\`, while the server only filters the `/` charact…
GHSA-2rhw-8953-48q3High· 5.9Duplicate Advisory: Grav: Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset-map.php` Static Asset Server (`index.php`)
Duplicate Advisory: Grav: Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset-map.php` Static Asset Server (`index.php`)
CVE-2026-73973Medium· 5.5Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems
Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 7.0.0, check-plugins/logfile/logfile accepted a free-form --filename path and opened it as root when invoked through the…
CVE-2026-52875NoneStreambert is a cross-platform Electron Desktop App to stream and download video content
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.6.0, the perform-scheduled-backup IPC handler in src/ipc/storage.js takes settings.path from a renderer-supplied object and uses the res…
CVE-2026-52872High· 8.8Streambert is a cross-platform Electron Desktop App to stream and download video content
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.5.0, the downloadSubtitleFile utility in src/ipc/downloads.js, reached through the run-download IPC channel, accepts a renderer-supplied…
CVE-2026-50186High· 8.84gaBoards is a boards system for realtime project management
4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards allows an authenticated project manager to supply traversal sequences in the filename parameter of GET /exports/:id/:filename. In server/api/controll…