CWE-22
CVEs classified under CWE-22, newest first.
1061 CVEsRSS
GHSA-cw6h-ffmh-x6vhMedium· 6.5Anki: User scripts in iframes have access to the internal Anki API
Anki: User scripts in iframes have access to the internal Anki API
GHSA-f4xh-w4cj-qxq8High· 7.7LangSmith SDK TracingMiddleware: Arbitrary server-side file read
LangSmith SDK TracingMiddleware: Arbitrary server-side file read
GHSA-4xgf-cpjx-pc3jMedium· 5.3pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size
pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size
GHSA-cc8f-fcx3-gpjrHigh· 7.7SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
GHSA-869j-r97x-hx2gHighAnki's local HTTP server does not sufficiently validate requests
Anki's local HTTP server does not sufficiently validate requests
GHSA-22cj-m4wf-fv2cHigh· 7.5PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal
PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal
GHSA-j7qx-p75m-wp7gHigh· 7.5PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage
PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage
GHSA-p4pj-vh7h-6cqhHigh· 7.5PraisonAI: Unauthenticated Local File Inclusion via agent_file path in PraisonAI Jobs API
PraisonAI: Unauthenticated Local File Inclusion via agent_file path in PraisonAI Jobs API
GHSA-2rcg-mm5h-xchxHigh· 7.5PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal
PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal
GHSA-gcq3-mfvh-3x25High· 7.3PraisonAI Code agent tools fail open without a workspace boundary
PraisonAI Code agent tools fail open without a workspace boundary
GHSA-f44v-7qgw-9gh9High· 8.1PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion
PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion
GHSA-29w3-p9w9-wc47Critical· 9.1PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation
PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation
CVE-2026-12565Medium· 5.3BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284
BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284
CVE-2026-12568Medium· 6.5BBOT: Arbitrary File Write in postman_download Module
BBOT: Arbitrary File Write in postman_download Module
CVE-2026-12567Low· 2.2BBOT: Symlink-Following Arbitrary Write via github_workflows Module
BBOT: Symlink-Following Arbitrary Write via github_workflows Module
CVE-2026-54319Medium· 4.2Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape
Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape
GHSA-hxpf-9xvq-wph8Critical· 9.6netlicensing-mcp: REST Path Traversal Bypasses Token Redaction
netlicensing-mcp: REST Path Traversal Bypasses Token Redaction
GHSA-2jq4-q6vv-4cp3Critical· 9.6Crawl4AI: Arbitrary file write (path traversal) in crawler downloads can lead to RCE
Crawl4AI: Arbitrary file write (path traversal) in crawler downloads can lead to RCE
CVE-2026-20181Critical· 9.1A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device
A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid ad…
CVE-2026-54014Medium· 4.3Open WebUI: Sibling-Prefix Path Traversal via /cache/{path}
Open WebUI: Sibling-Prefix Path Traversal via /cache/{path}
CVE-2026-54017High· 7.7Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversal
Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversal
CVE-2026-50203Critical· 9.1Apache Airflow SFTP provider: Path traversal in SFTPHook.retrieve_directory
Apache Airflow SFTP provider: Path traversal in SFTPHook.retrieve_directory
CVE-2025-26240High· 8.4PoCpdfkit: Path traversal in from_string
pdfkit: Path traversal in from_string
GHSA-5v23-73v4-w2fpHigh· 7.5Duplicate Advisory: picklescan has Arbitrary file read using `io.FileIO`
Duplicate Advisory: picklescan has Arbitrary file read using `io.FileIO`
CVE-2026-55760High· 7.5handlebars.java FileTemplateLoader Path Traversal
handlebars.java FileTemplateLoader Path Traversal
CVE-2026-54286Medium· 5.9hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
GHSA-gr75-jv2w-4656Medium· 5.1LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders
LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders
CVE-2026-42867Medium· 6.5Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint
Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint
CVE-2026-49465Medium· 7.7n8n: Git Node Clone and Push Operations Bypass File Sandbox
n8n: Git Node Clone and Push Operations Bypass File Sandbox
CVE-2026-49406Medium· 5.5Deno: BYONM module resolution allows `package.json` main path traversal to bypass `--allow-read` restrictions
Deno: BYONM module resolution allows `package.json` main path traversal to bypass `--allow-read` restrictions