CWE-22
CVEs classified under CWE-22, newest first.
1061 CVEsRSS
CVE-2026-53766Medium· 6.1chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots
chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots
CVE-2026-69148High· 7.1MLflow is an open source AI engineering platform for agents, large language models, and machine learning models
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion accepts a run_id or model_id after _validate_source_run() or _validate_source_model() in…
GHSA-92hr-gmr6-h8cpMediumEtherpad addressed weak token RNG, login timing, plugin path handling, API request handling
Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling
CVE-2026-46345High· 8.4compliance-trestle is a tooling platform for managing compliance as code
compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the `-o/--output` argument in `trestle author jinja` allows writing files outside the intended workspace. The application does …
CVE-2026-15056Medium· 6.5The StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.1.1 via the parse_file_path function
The StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.1.1 via the parse_file_path function. This mak…
CVE-2026-14524Critical· 9.1The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8
The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8. This makes it possible…
CVE-2026-74764NonePandora contains a path traversal vulnerability in its TAR archive extraction functionality
Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submitted TAR archive, the extractor passed archive member names directly to Python's tarfile.TarFile.extract() without applyi…
CVE-2026-18855Critical· 9.1The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to, and including, 7.9.4 This makes it possible for unauthen…
The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to, and including, 7.9.4 This makes it possible for unauthen…
CVE-2026-72820Medium· 4.9Grav versions before 2.0.13 fail to properly validate backup profile root paths, allowing attackers to archive directories outside GRAV_ROOT when not in the hard-coded deny-list
Grav versions before 2.0.13 fail to properly validate backup profile root paths, allowing attackers to archive directories outside GRAV_ROOT when not in the hard-coded deny-list. Attackers with profile editor access can configure backup …
CVE-2026-72814Medium· 5.3The actix-files crate (actix_files) before version 0.6.10 contains an information exposure vulnerability
The actix-files crate (actix_files) before version 0.6.10 contains an information exposure vulnerability. When a non-existing folder is passed as the serve_from argument to Files::new(), the mount path defaults to an empty path; the serv…
CVE-2026-55156Medium· 5.3Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints
Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints
CVE-2026-73653Critical· 9.4Vitest is a testing framework powered by Vite
Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accep…
CVE-2026-73659High· 8.1Trigger.dev is the open-source platform for building AI workflows in TypeScript
Trigger.dev is the open-source platform for building AI workflows in TypeScript. From 4.4.2 until 4.5.0, the packet presign routes in apps/webapp/app/routes/api.v1.packets.$.ts pass a caller-controlled filename through resolveStoreProtoc…
CVE-2026-73658High· 8.2Trigger.dev is a platform for building and deploying fully managed AI agents and workflows
Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() and Aws4FetchClient.presign() in apps/webapp/app/v3/objectStoreClient.server.ts assign us…
CVE-2026-73657Medium· 4.2Trigger.dev is a platform for building and deploying fully managed AI agents and workflows
Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.4, `POST /api/v1/runs/:runParam/replay` in apps/webapp/app/routes/api.v1.runs.$runParam.replay.ts uses `prisma.taskRun.…
CVE-2026-70460High· 8.1rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options
rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options. Attackers with…
CVE-2026-67613Medium· 4.9CyberPanel before 3.0.0 contains a path traversal vulnerability that allows authenticated administrators to read arbitrary files from the server filesystem by supplying unsanitized file paths to the cloudAPI ReadReport endpoint
CyberPanel before 3.0.0 contains a path traversal vulnerability that allows authenticated administrators to read arbitrary files from the server filesystem by supplying unsanitized file paths to the cloudAPI ReadReport endpoint. Attacker…
CVE-2026-73509High· 7.6OpenList a file list program that supports multiple storage
OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename handler in server/handles/fsbatch.go authorizes only the source directory produced by user.JoinPath(req.SrcDir) and valid…
GHSA-rm43-82j9-r4mjHighatomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read
atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read
CVE-2026-45774Mediumcompliance-trestle is a tooling platform for managing compliance as code
compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the compliance-trestle library's profile import mechanism resolves `trestle://` URIs and relative file paths by joining them wi…
CVE-2026-48099High· 7.1WsgiDAV is a generic and extendable WebDAV server based on WSGI
WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path containing an encoded parent-directory segment to escape the configured filesystem share root in a specific path lay…
CVE-2026-73291High· 7.1Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby
Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr's ImageProxy in server/lib/imageproxy.ts uses the upstream ETag and Content-Type response headers to build a cache fi…
CVE-2026-16033High· 8.5A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation
A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths from es…
CVE-2026-66898Critical· 9.9A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations
A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names c…
CVE-2026-64826Medium· 6.5rConfig before 8.2.13 contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying unsanitized directory traversal sequences in the filename GET parameter of the download_export() metho…
rConfig before 8.2.13 contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying unsanitized directory traversal sequences in the filename GET parameter of the download_export() metho…
CVE-2026-73407NoneBudibase is an open-source low-code platform
Budibase is an open-source low-code platform. Prior to 3.40.1, RestIntegration._req in packages/server/src/integrations/rest.ts attached credentials from getAuthHeaders and defaultHeaders without requiring the final request destination t…
CVE-2026-19594High· 8.1Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded `..` identifier path s…
Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded `..` identifier path s…
CVE-2026-65939Medium· 6.8In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.
CVE-2026-66382Medium· 4.3An authenticated user may write files outside the intended Artifactory work directory under specific conditions.
An authenticated user may write files outside the intended Artifactory work directory under specific conditions.
CVE-2026-66381Medium· 5.3A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions.
A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions.