CWE-22
CVEs classified under CWE-22, newest first.
1061 CVEsRSS
CVE-2026-44024Critical· 9.8PoCFluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
CVE-2026-48944Medium· 6.5The K2 frontend article-save handler accepts an `attachment[N][existing]` POST field that is concatenated with `JPATH_SITE/` and passed to `JFile::copy()`
The K2 frontend article-save handler accepts an `attachment[N][existing]` POST field that is concatenated with `JPATH_SITE/` and passed to `JFile::copy()`. `JPath::clean` does NOT strip `..`, and there is no allow-list of source paths. A…
CVE-2026-48776Medium· 4.2LangGraph SDK has unsafe URL path construction
LangGraph SDK has unsafe URL path construction
CVE-2026-49219Medium· 5.5ImageMagick: Policy Bypass can read disallowed files via symlink
ImageMagick: Policy Bypass can read disallowed files via symlink
CVE-2026-57296High· 8.8Jenkins External Workspace Manager Plugin has a path traversal vulnerability
Jenkins External Workspace Manager Plugin has a path traversal vulnerability
CVE-2026-11940High· 7.3tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself. The extraction fallback validated the symlink at it's…
tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself. The extraction fallback validated the symlink at it's…
CVE-2026-52811CriticalGogs: UploadRepoFiles writes outside repo working tree via committed parent sym
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym
CVE-2026-53925High· 7.8Glances has arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configuration
Glances has arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configuration
CVE-2026-54557Medium· 5.5mise HTTP backend uses raw version path for install symlink destination
mise HTTP backend uses raw version path for install symlink destination
CVE-2026-55488HighmotionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read
motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read
GHSA-qxvg-h7q2-hcxhCritical· 9.8motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)
motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)
CVE-2026-48126High· 8.2Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir
Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir
CVE-2026-53779High· 7.5WebP Server Go < 0.15.0 Path Traversal via Backslash Encoding on Windows
WebP Server Go through 0.14.4 contains a path traversal vulnerability on Windows that allows unauthenticated attackers to read files outside the configured IMG_PATH directory by sending requests with percent-encoded backslashes (%5C) tha…
CVE-2026-42129High· 7.7A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.
A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.
CVE-2026-10601Medium· 5.4A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints
A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak inter…
CVE-2026-54293High· 7.5PoCNLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Prior to 3.10.0-rc1, nltk.data.load() in NLTK is vulnerable to path tr…
CVE-2026-31978Medium· 6.5motionEye has an Arbitrary File Read via Path Traversal in Picture/Movie Preview Endpoint
motionEye has an Arbitrary File Read via Path Traversal in Picture/Movie Preview Endpoint
GHSA-74p7-6h78-gw8pHighskillctl: argument injection, path traversal in --dest, FIFO/device DoS, hardlink exfiltration, and commit-trailer forgery
skillctl: argument injection, path traversal in --dest, FIFO/device DoS, hardlink exfiltration, and commit-trailer forgery
CVE-2026-54352Critical· 9.6Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload
Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload
CVE-2026-54414Critical· 9.8FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover
FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover. The upload filename is validated by F…
GHSA-fwh2-95jw-g4j6High· 8.8Duplicate Advisory: PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling
Duplicate Advisory: PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling
GHSA-2h46-9x5w-4wf7MediumEntire CLI: Path traversal in checkpoint session metadata allows arbitrary file write during resume/rewind
Entire CLI: Path traversal in checkpoint session metadata allows arbitrary file write during resume/rewind
CVE-2026-11769MediumGrafana Operator: Privilege escalation from namespace admin to cluster admin via GrafanaDashboard jsonnetLib fileName
Grafana Operator: Privilege escalation from namespace admin to cluster admin via GrafanaDashboard jsonnetLib fileName
CVE-2026-55878High· 7.8symfony/ux-toolkit: Path Traversal Allows Arbitrary File Write and Read via Crafted Recipe Manifest
symfony/ux-toolkit: Path Traversal Allows Arbitrary File Write and Read via Crafted Recipe Manifest
GHSA-9c83-rr99-vfwjMediumMCPVault: PathFilter restricted directories (.git/.obsidian/node_modules) only denied at vault root, not nested
MCPVault: PathFilter restricted directories (.git/.obsidian/node_modules) only denied at vault root, not nested
GHSA-2fmp-9rvw-hc96High· 7.1Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning
Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning
GHSA-jvcm-f35g-w78pMedium· 6.5Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directory
Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directory
GHSA-6x2m-p4xp-wg22Medium· 5.5Network-AI: EnvironmentManager.backup() follows symlinked directories and copies files outside the environment root into backups
Network-AI: EnvironmentManager.backup() follows symlinked directories and copies files outside the environment root into backups
GHSA-48x2-6pr9-2jjfMedium· 6.1Network-AI: EnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment data
Network-AI: EnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment data
GHSA-c795-2g9c-j48mHigh· 8.2EverOS: Path traversal in EverOS /api/v1/memory/add via unvalidated sender_id
EverOS: Path traversal in EverOS /api/v1/memory/add via unvalidated sender_id