VulnSea

CWE-22

CVEs classified under CWE-22, newest first.

1061 CVEsRSS

GHSA-cw6h-ffmh-x6vhMedium· 6.5
3mo ago

Anki: User scripts in iframes have access to the internal Anki API

Anki: User scripts in iframes have access to the internal Anki API

▾ Sunlitaqt · aqtvia GHSA
GHSA-f4xh-w4cj-qxq8High· 7.7
3mo ago

LangSmith SDK TracingMiddleware: Arbitrary server-side file read

LangSmith SDK TracingMiddleware: Arbitrary server-side file read

▾ Twilightlangsmith · langsmithvia GHSA
GHSA-4xgf-cpjx-pc3jMedium· 5.3
3mo ago

pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size

pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size

▾ Sunlitpydantic-settings · pydantic-settingsvia GHSA
GHSA-cc8f-fcx3-gpjrHigh· 7.7
3mo ago

SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter

SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter

▾ Twilightsurrealdb · surrealdbvia GHSA
GHSA-869j-r97x-hx2gHigh
3mo ago

Anki's local HTTP server does not sufficiently validate requests

Anki's local HTTP server does not sufficiently validate requests

▾ Twilightaqt · aqtvia GHSA
GHSA-22cj-m4wf-fv2cHigh· 7.5
3mo ago

PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal

PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-j7qx-p75m-wp7gHigh· 7.5
3mo ago

PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage

PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-p4pj-vh7h-6cqhHigh· 7.5
3mo ago

PraisonAI: Unauthenticated Local File Inclusion via agent_file path in PraisonAI Jobs API

PraisonAI: Unauthenticated Local File Inclusion via agent_file path in PraisonAI Jobs API

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-2rcg-mm5h-xchxHigh· 7.5
3mo ago

PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal

PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal

▾ Twilightpraisonaiagents · praisonaiagentsvia GHSA
GHSA-gcq3-mfvh-3x25High· 7.3
3mo ago

PraisonAI Code agent tools fail open without a workspace boundary

PraisonAI Code agent tools fail open without a workspace boundary

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-f44v-7qgw-9gh9High· 8.1
3mo ago

PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion

PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-29w3-p9w9-wc47Critical· 9.1
3mo ago

PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation

PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation

▾ Midnightpraisonai · praisonaivia GHSA
CVE-2026-12565Medium· 5.3
3mo ago

BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284

BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284

▾ Sunlitbbot · bbotEPSS 0.21%via GHSA
CVE-2026-12568Medium· 6.5
3mo ago

BBOT: Arbitrary File Write in postman_download Module

BBOT: Arbitrary File Write in postman_download Module

▾ Sunlitbbot · bbotEPSS 0.25%via GHSA
CVE-2026-12567Low· 2.2
3mo ago

BBOT: Symlink-Following Arbitrary Write via github_workflows Module

BBOT: Symlink-Following Arbitrary Write via github_workflows Module

▾ Sunlitbbot · bbotEPSS 0.09%via GHSA
CVE-2026-54319Medium· 4.2
3mo ago

Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape

Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape

▾ Sunlitdaytonaio · github.com/daytonaio/daytonaEPSS 0.24%via GHSA
GHSA-hxpf-9xvq-wph8Critical· 9.6
3mo ago

netlicensing-mcp: REST Path Traversal Bypasses Token Redaction

netlicensing-mcp: REST Path Traversal Bypasses Token Redaction

▾ Midnightnetlicensing-mcp · netlicensing-mcpvia GHSA
GHSA-2jq4-q6vv-4cp3Critical· 9.6
3mo ago

Crawl4AI: Arbitrary file write (path traversal) in crawler downloads can lead to RCE

Crawl4AI: Arbitrary file write (path traversal) in crawler downloads can lead to RCE

▾ Midnightcrawl4ai · crawl4aivia GHSA
CVE-2026-20181Critical· 9.1
3mo ago

A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device

A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid ad…

▾ Midnightcisco · identity_services_engineEPSS 8.9%via NVD
CVE-2026-54014Medium· 4.3
3mo ago

Open WebUI: Sibling-Prefix Path Traversal via /cache/{path}

Open WebUI: Sibling-Prefix Path Traversal via /cache/{path}

▾ Sunlitopen-webui · open-webuiEPSS 0.36%via GHSA
CVE-2026-54017High· 7.7
3mo ago

Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversal

Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversal

▾ Twilightopen-webui · open-webuiEPSS 0.52%via GHSA
CVE-2026-50203Critical· 9.1
3mo ago

Apache Airflow SFTP provider: Path traversal in SFTPHook.retrieve_directory

Apache Airflow SFTP provider: Path traversal in SFTPHook.retrieve_directory

▾ Midnightapache-airflow-providers-sftp · apache-airflow-providers-sftpEPSS 0.88%via OSV
CVE-2025-26240High· 8.4PoC
3mo ago

pdfkit: Path traversal in from_string

pdfkit: Path traversal in from_string

▾ Midnightpdfkit · pdfkitEPSS 0.39%via GHSA
GHSA-5v23-73v4-w2fpHigh· 7.5
3mo ago

Duplicate Advisory: picklescan has Arbitrary file read using `io.FileIO`

Duplicate Advisory: picklescan has Arbitrary file read using `io.FileIO`

▾ Twilightpicklescan · picklescanvia GHSA
CVE-2026-55760High· 7.5
3mo ago

handlebars.java FileTemplateLoader Path Traversal

handlebars.java FileTemplateLoader Path Traversal

▾ Twilightgithub · com.github.jknack:handlebarsEPSS 0.53%via GHSA
CVE-2026-54286Medium· 5.9
3mo ago

hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)

hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)

▾ Sunlithono · honoEPSS 0.43%via GHSA
GHSA-gr75-jv2w-4656Medium· 5.1
3mo ago

LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders

LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders

▾ Sunlitlangchain · langchainvia GHSA
CVE-2026-42867Medium· 6.5
3mo ago

Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint

Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint

▾ Sunlitlangflow · langflowEPSS 0.47%via GHSA
CVE-2026-49465Medium· 7.7
3mo ago

n8n: Git Node Clone and Push Operations Bypass File Sandbox

n8n: Git Node Clone and Push Operations Bypass File Sandbox

▾ Sunlitn8n · n8nEPSS 0.54%via GHSA
CVE-2026-49406Medium· 5.5
3mo ago

Deno: BYONM module resolution allows `package.json` main path traversal to bypass `--allow-read` restrictions

Deno: BYONM module resolution allows `package.json` main path traversal to bypass `--allow-read` restrictions

▾ Sunlitdeno · denoEPSS 0.18%via GHSA
CWE-22 vulnerabilities (CVEs) — page 28 · VulnSea