VulnSea

CWE-41

CVEs classified under CWE-41, newest first.

14 CVEsRSS

CVE-2026-93709None
today

Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard in the AutoPage handler. The handler compares the request path against the layout directory name as text, while the…

Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard in the AutoPage handler. The handler compares the request path against the layout directory name as text, while the…

Sunlitvia NVD
CVE-2026-57441High· 8.4
1w ago

MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault

MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.4, PathFilter in src/pathfilter.ts compiles restricted-directory patterns case-sensitively and compares paths without ca…

Twilightbitbonsai · mcpvaultEPSS 0.17%via NVD
CVE-2026-89768Low· 2.3
1w ago

kernel: Linux kernel: Information disclosure via incorrect path derivation in nested overlayfs (CVE-2026-89768)

A flaw was found in the Linux kernel's filesystem (fs) component. When using nested overlay filesystems (overlayfs), a local user could exploit an issue where the backing_file_open() function incorrectly derives the path for mapped files. …

SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.19%via CSAF
CVE-2026-85978Critical· 9.8
1w ago

An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform

An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform. A path normalization discrepancy between the authentication filter and the servlet dispatcher allows a crafted request to …

MidnightPerforce · AkanaEPSS 0.88%via NVD
CVE-2026-73019Medium· 4.3
2w ago

Improper resolution of path equivalence in Windows URL Moniker allows an unauthorized attacker to bypass a security feature over a network.

Improper resolution of path equivalence in Windows URL Moniker allows an unauthorized attacker to bypass a security feature over a network.

Sunlitmicrosoft · windows_10_1607EPSS 0.73%via NVD
CVE-2026-66835High· 8.2
3w ago

Path Equivalence vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by prefixing the request path with an extra slash. httpd_request:validate_uri/1 normal…

Path Equivalence vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by prefixing the request path with an extra slash. httpd_request:validate_uri/1 normal…

TwilightErlang · otpEPSS 0.64%via NVD
CVE-2026-62384High· 7.5
1mo ago

NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root

NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path separators i…

Twilightnltk · nltkEPSS 0.56%via NVD
CVE-2026-72835Medium· 6.8
1mo ago

filebrowser versions before v2.63.21 fail to canonicalize paths before evaluating access rules, allowing authenticated users to bypass administrator-defined deny rules using case-variant or backslash-separated paths

filebrowser versions before v2.63.21 fail to canonicalize paths before evaluating access rules, allowing authenticated users to bypass administrator-defined deny rules using case-variant or backslash-separated paths. Attackers can reques…

SunlitEPSS 0.41%via NVD
CVE-2026-18427High· 7.5
1mo ago

@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass

@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent directory segments, but it did not canonicalize dot segments, duplicate slashes, encoded dot…

TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.43%via NVD
CVE-2026-66064Medium· 5.3
1mo ago

goshs has ACL Bypass & Path Traversal

goshs has ACL Bypass & Path Traversal

Sunlitpatrickhener · github.com/patrickhener/goshs/v2EPSS 0.31%via GHSA
CVE-2026-50568Low· 3.6
1mo ago

Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape

Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape

Sunlitfission · github.com/fission/fissionEPSS 0.11%via GHSA
GHSA-j99q-93c9-h869Medium
3mo ago

MCPVault: PathFilter restricted-directory deny-list bypass via case and trailing dot/space equivalence

MCPVault: PathFilter restricted-directory deny-list bypass via case and trailing dot/space equivalence

Sunlitbitbonsai · @bitbonsai/mcpvaultvia GHSA
CVE-2026-49401Medium· 5.2
3mo ago

Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)

Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)

Sunlitdeno · denoEPSS 0.20%via GHSA
CVE-2026-34451Medium· 5.4
5mo ago

Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications

Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From version 0.79.0 to before version 0.81.0, the local filesystem memory tool in the Anthropic TypeScript SDK validated …

Sunlitanthropic · claude_sdk_for_typescriptEPSS 0.35%via NVD
CWE-41 vulnerabilities (CVEs) · VulnSea