CWE-22
CVEs classified under CWE-22, newest first.
1061 CVEsRSS
CVE-2026-52830Critical· 9.4fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection
fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection
CVE-2026-50180HighLangroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read
Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read
CVE-2026-50181High· 7.1PoCLangroid: Path traversal in the file tools allows read/write outside configured current directory
Langroid: Path traversal in the file tools allows read/write outside configured current directory
CVE-2026-20191High· 7.5A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container. This vulnerability is due to insufficient validation of user-supplied input
A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container. This vulnerability is due to insufficient validation of user-supplied input. An attack…
CVE-2026-50162Medium· 5.3oras-go: oras-go: File store write outside working directory via symlink traversal (CVE-2026-50162)
A flaw was found in oras-go. The file content store, intended to confine writes to a specified working directory, does not properly account for symbolic link (symlink) traversal. A remote attacker, by providing a specially crafted blob tit…
CVE-2026-50163High· 7.1`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution
`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution
GHSA-j6hm-v3x2-qv6jLowland.oras:oras-java-sdk: Symlink-based path traversal in ArchiveUtils.untar / unzip allows arbitrary file write outside extraction directory
land.oras:oras-java-sdk: Symlink-based path traversal in ArchiveUtils.untar / unzip allows arbitrary file write outside extraction directory
GHSA-2wwr-9x6f-88gpMedium· 5.3EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
CVE-2026-12243High· 7.5PoCnltk: NLTK: Information disclosure via path traversal vulnerability (CVE-2026-12243)
A flaw was found in NLTK. An attacker can exploit a path traversal vulnerability by providing specially crafted input to `nltk.data.load()` or `nltk.data.find()`. This allows the attacker to read arbitrary files accessible to the Python pr…
CVE-2026-58015Medium· 5.9A flaw was found in GLib
A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_co…
CVE-2026-57079Medium· 5.3Net::BitTorrent versions before 2.1.0 for Perl write files outside the download directory via path traversal in peer-supplied metadata. Net::BitTorrent validates file path components only on the .torrent-file ingest path
Net::BitTorrent versions before 2.1.0 for Perl write files outside the download directory via path traversal in peer-supplied metadata. Net::BitTorrent validates file path components only on the .torrent-file ingest path. The peer and m…
CVE-2026-8023High· 7.5PoCZephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STATIC_FS, available when CONFIG_FILE_SYSTEM is enabled) that serves files from a configured root directory
Zephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STATIC_FS, available when CONFIG_FILE_SYSTEM is enabled) that serves files from a configured root directory. Before this fix, both …
CVE-2026-13528High· 7.3A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.04-jdk8-SNAPSHOT
A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.04-jdk8-SNAPSHOT. The impacted element is the function generateUploadPath of the file yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/service/file/…
CVE-2026-13509Medium· 6.3A vulnerability has been found in RAGapp up to 0.1.5
A vulnerability has been found in RAGapp up to 0.1.5. Affected is the function FileHandler.upload_file/FileHandler.remove_file of the file src/ragapp/backend/controllers/files.py of the component Knowledge File Handler. Such manipulation…
CVE-2026-13503Medium· 5.3A vulnerability was detected in antlr ANTLR4 up to 4.13.2
A vulnerability was detected in antlr ANTLR4 up to 4.13.2. Affected by this issue is the function getImportedVocabFile of the file tool/src/org/antlr/v4/parse/TokenVocabParser.java of the component tokenVocab Grammar Option Handler. The …
GHSA-fr4h-3cph-29xvHigh· 7.1pnpm: Hoisted install imports lockfile alias outside node_modules
pnpm: Hoisted install imports lockfile alias outside node_modules
GHSA-72r4-9c5j-mj57High· 7.1pnpm: `patch-remove` could delete project-selected files outside the patches directory
pnpm: `patch-remove` could delete project-selected files outside the patches directory
GHSA-qrv3-253h-g69cHigh· 8.2pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config
pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config
CVE-2026-55677High· 7.5github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy (CVE-2026-55677)
A flaw was found in Echo, a Go web framework. An attacker can exploit a disagreement in URL path decoding between the router and the static file handler. The router processes raw encoded paths, while the static file handler unescapes encod…
CVE-2026-49991High· 8.6RustFS is a distributed object storage system built in Rust
RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject permission on their own bucket can exploit a path traversal vulnerability in the Snowball auto-extract feature to write…
GHSA-3p34-w4f6-5xh2High· 7.5better-helperjs Vulnerable to Directory Traversal via String Prefix Bypass in Static Server
better-helperjs Vulnerable to Directory Traversal via String Prefix Bypass in Static Server
CVE-2026-48820MediumCakePHP: View::element() is missing a path containment check
CakePHP: View::element() is missing a path containment check
GHSA-rp72-5v5q-2446Low@cardano402/mcp-server missing spending limits, LAN-exposed HTTP transport, and SSRF via catalog.server.url
@cardano402/mcp-server missing spending limits, LAN-exposed HTTP transport, and SSRF via catalog.server.url
CVE-2026-49342Medium· 5.3YARD static cache reads raw traversal paths before router sanitization
YARD static cache reads raw traversal paths before router sanitization
CVE-2026-50015High· 7.3pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)
pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)
CVE-2026-53519Critical· 9.1PoCNezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key
Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key
CVE-2026-49340High· 8.1gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host
CVE-2026-49339High· 7.1gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists
CVE-2026-55699Medium· 6.5pnpm: Reserved bin name deletes PNPM_HOME during global remove
pnpm: Reserved bin name deletes PNPM_HOME during global remove
CVE-2026-55700High· 7.1pnpm: `stage download` writes outside its destination directory via manifest name/version traversal
pnpm: `stage download` writes outside its destination directory via manifest name/version traversal