VulnSea

CWE-22

CVEs classified under CWE-22, newest first.

1061 CVEsRSS

CVE-2026-54545High· 7.1
2mo ago

@wakaru/cli arbitrary file write during bundle unpack

@wakaru/cli arbitrary file write during bundle unpack

▾ Twilightwakaru · @wakaru/cliEPSS 0.20%via GHSA
CVE-2026-45623High· 7.5
2mo ago

postcss: PostCSS: Information disclosure and denial of service via crafted CSS input (CVE-2026-45623)

A flaw was found in PostCSS, a tool that processes CSS files. An attacker who provides specially crafted CSS input containing a malicious source map comment can cause the system to read arbitrary files from the local filesystem. This can l…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.61%via CSAF
CVE-2026-66007Medium· 6.5
2mo ago

datasets: Datasets: Information disclosure via path traversal vulnerability (CVE-2026-66007)

A flaw was found in datasets. This path traversal vulnerability allows a remote attacker to read arbitrary local files. By providing specially crafted file names in the metadata, an attacker can trick the system into including sensitive lo…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.79%via CSAF
GHSA-95cv-r8x4-vh75High· 7.6
2mo ago

OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal

OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal

▾ TwilightOpenListTeam · github.com/OpenListTeam/OpenList/v4via GHSA
CVE-2026-59221High· 7.7
2mo ago

open-webui terminal proxy path traversal guard bypass via 9x encoded traversal

open-webui terminal proxy path traversal guard bypass via 9x encoded traversal

▾ Twilightopen-webui · open-webuiEPSS 0.48%via GHSA
CVE-2026-15074High· 7.5
2mo ago

@fastify/static vulnerable to route guard bypass via path traversal

@fastify/static vulnerable to route guard bypass via path traversal

▾ Twilightfastify · @fastify/staticEPSS 0.67%via GHSA
CVE-2026-55607High
2mo ago

Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution

Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution

▾ Twilightanthropic-ai · @anthropic-ai/claude-codeEPSS 0.69%via GHSA
CVE-2026-59864Critical
2mo ago

Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions

Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions

▾ MidnightMicrosoft · Microsoft.OpenApi.KiotaEPSS 1.3%via GHSA
CVE-2026-59867High· 7.1
2mo ago

Microsoft Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref

Microsoft Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref

▾ TwilightMicrosoft · Microsoft.OpenApi.KiotaEPSS 2.4%via GHSA
CVE-2026-59863High
2mo ago

Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF

Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF

▾ TwilightMicrosoft · Microsoft.OpenApi.KiotaEPSS 1.4%via GHSA
CVE-2026-59866High
2mo ago

Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName

Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName

▾ TwilightMicrosoft · Microsoft.OpenApi.KiotaEPSS 1.4%via GHSA
GHSA-p5rm-jg5c-8c77Medium
2mo ago

Microsoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass)

Microsoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass)

▾ SunlitMicrosoft · Microsoft.OpenApi.Kiotavia GHSA
CVE-2026-61632Medium· 5.3
2mo ago

PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path

PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path

▾ Sunlitpymdown-extensions · pymdown-extensionsEPSS 0.40%via OSV
GHSA-r28c-9q8g-f849High· 7.5
2mo ago

PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure

PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure

▾ Twilightpostcss · postcssvia GHSA
CVE-2026-65919High· 7.5PoC
2mo ago

Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api/system/fileDownload endpoints that pass user-supplied file parameters directly to os.Open without path validation

Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api/system/fileDownload endpoints that pass user-supplied file parameters directly to os.Open without path validation. A…

▾ Midnightmeshery · mesheryEPSS 2.1%via NVD
GHSA-gf29-4f56-r2jfHigh
2mo ago

n8n: Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction

n8n: Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction

▾ Twilightn8n · n8nvia GHSA
GHSA-pf2q-pxhf-hgmwMedium
2mo ago

n8n: Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base Directory

n8n: Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base Directory

▾ Sunlitn8n · n8nvia GHSA
CVE-2026-55554Low
2mo ago

Dompdf: Chroot Validation Bypass

Dompdf: Chroot Validation Bypass

▾ Sunlitdompdf · dompdf/dompdfEPSS 0.45%via GHSA
CVE-2026-56722Medium
2mo ago

Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI

Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI

▾ Sunlitdompdf · dompdf/dompdfEPSS 0.45%via GHSA
GHSA-p63j-vcc4-9vmvCritical· 9.4
2mo ago

@vitest/browser: Browser Mode provider commands bypass the file-access permission gate

@vitest/browser: Browser Mode provider commands bypass the file-access permission gate

▾ Midnightvitest · @vitest/browservia GHSA
GHSA-frvp-7c67-39w9Medium· 5.9
2mo ago

Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)

Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)

▾ Sunlithono · @hono/node-servervia GHSA
CVE-2026-59946Medium· 6.1
2mo ago

Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files

Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files

▾ Sunlitcomposer · composer/composerEPSS 0.17%via GHSA
CVE-2026-62843Medium· 6.8
2mo ago

File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)

File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)

▾ Sunlitfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.39%via GHSA
CVE-2026-55667High· 8.2
2mo ago

File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup

File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup

▾ Twilightfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.49%via GHSA
CVE-2026-55668Medium· 6.3
2mo ago

File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope

File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope

▾ Sunlitfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.38%via GHSA
CVE-2026-59948High· 7.0
2mo ago

Composer: Arbitrary file write outside vendor via malicious transitive package name

Composer: Arbitrary file write outside vendor via malicious transitive package name

▾ Twilightcomposer · composer/composerEPSS 0.16%via GHSA
CVE-2026-16219Medium· 6.3PoC
2mo ago

A flaw has been found in Croogo CMS up to 4.0.7

A flaw has been found in Croogo CMS up to 4.0.7. This affects the function FileManager::isEditable of the file FileManager/src/Utility/FileManager.php of the component Admin File Manager. This manipulation causes path traversal. The atta…

▾ TwilightEPSS 0.43%via NVD
CVE-2025-71394None
2mo ago

SurrealDB versions before 2.2.2 contain a local file read vulnerability in the DEFINE ANALYZER statement that allows authenticated users to read arbitrary files on the file system

SurrealDB versions before 2.2.2 contain a local file read vulnerability in the DEFINE ANALYZER statement that allows authenticated users to read arbitrary files on the file system. Attackers with root, namespace, or database level privil…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-15631High· 8.7
2mo ago

Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix

Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in WebSocketProxy.findUpstream resolves…

▾ TwilightEPSS 0.50%via NVD
CVE-2026-16088Medium· 4.7
2mo ago

A vulnerability was detected in halo-dev halo up to 2.24.2

A vulnerability was detected in halo-dev halo up to 2.24.2. Affected by this vulnerability is the function Download of the file MigrationEndpoint.java of the component Files Backup Endpoint. Performing a manipulation results in path trav…

▾ SunlitEPSS 0.49%via NVD
CWE-22 vulnerabilities (CVEs) — page 23 · VulnSea