Threats Tagged 'cwe-22'
View all threats tagged with 'cwe-22'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-22'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-49163: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Microsoft Application Insights ProfilerCVE-2026-49163 0 CVE-2026-49163 is a high-severity path traversal vulnerability in Microsoft Application Insights Profiler. It allows an authorized attacker to bypass pathname restrictions and potentially elevate privileges over a network. An official fix is available from Microsoft to address this issue. Join the discussion | CVE Database V5 | 08/06/2026, 22:37:41 UTC Added: 08/07/2026, 00:27:01 UTC |
CVE-2026-71476: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in nrwl nxCVE-2026-71476 0 Nx versions from 20.8.0 until 22.7.7 and 23.0.2 contain a path traversal vulnerability in the self-hosted HTTP remote cache feature. This flaw allows a malicious or man-in-the-middle remote cache server to craft a tar archive that writes files outside the intended cache directory, potentially leading to remote code execution. The default local cache and Nx Cloud are not affected. The vulnerability is fixed in versions 22.7.7 and 23.0.2. Join the discussion | CVE Database V5 | 08/06/2026, 20:07:09 UTC Added: 08/06/2026, 22:13:35 UTC |
CVE-2026-64677: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in ankitects ankiCVE-2026-64677 0 Anki versions prior to 25.09.3 contain a path traversal vulnerability in its local HTTP server endpoints. This flaw allows scripts from shared decks or malicious websites, combined with an origin-check bypass, to read local files by exploiting inadequate path restrictions. The issue is resolved in version 25.09.3. Join the discussion | CVE Database V5 | 08/06/2026, 17:21:43 UTC Added: 08/06/2026, 22:13:27 UTC |
CVE-2026-61632: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in facelessuser pymdown-extensionsCVE-2026-61632 0 PyMdown Extensions versions up to and including 10.21.3 contain a path traversal vulnerability in the b64 extension. This flaw allows an attacker controlling Markdown input to cause the extension to read and disclose arbitrary files with certain image extensions outside the intended base directory. The vulnerability is fixed in version 11.0. Join the discussion | CVE Database V5 | 08/06/2026, 20:59:20 UTC Added: 08/06/2026, 22:13:27 UTC |
CVE-2026-41861: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in CloudFoundry Foundation BOSHCVE-2026-41861 0 Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attacker to make the agent write a root-owned file with partially attacker-controlled body to any path ending in .network, and create any missing parent directories with mode 0777 via network Alias on Ubuntu. Affected versions: BOSH agent < v2.847.0 (jammy <= v1.1202, or noble <= v1.364). Lower bound unspecified in advisory ("All bosh agent versions"). Join the discussion | CVE Database V5 | 08/06/2026, 18:29:26 UTC Added: 08/06/2026, 22:13:22 UTC |
CVE-2026-18991: Path Traversal in nanocoai NanoClawCVE-2026-18991 0 A path traversal vulnerability exists in nanocoai NanoClaw up to version 2.0.64, specifically in the send_file component within the file container/agent-runner/src/mcp-tools/core.ts. This vulnerability can be exploited remotely without authentication. The issue has been publicly disclosed, but the project has not yet responded or issued a fix. Join the discussion | GCVE Database | 08/06/2026, 02:30:13 UTC Added: 08/06/2026, 18:17:15 UTC |
CVE-2026-19038: Path Traversal in MonomythDevelopment la-forge-mcpCVE-2026-19038 0 A security vulnerability has been detected in MonomythDevelopment la-forge-mcp 1.0.0. This issue affects the function screenshotElement of the file src/index.ts of the component screenshot_element Tool. Such manipulation of the argument output_name leads to path traversal. The attack can be executed remotely. Upgrading to version 1.1.1 is capable of addressing this issue. The name of the patch is 1102172c9adec4a619e241efd6bfb74f5b1f4332. Upgrading the affected component is advised. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. Join the discussion | GCVE Database | 08/06/2026, 12:45:10 UTC Added: 08/06/2026, 18:16:28 UTC |
CVE-2026-28146: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates)CVE-2026-28146 0 Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions. Join the discussion | CVE Database V5 | 08/06/2026, 14:27:12 UTC Added: 08/06/2026, 14:41:56 UTC |
CVE-2026-17556: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitHub Enterprise ServerCVE-2026-17556 0 A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and directories on the instance, including the entire user storage directory containing Git LFS objects, release assets, attachments, and avatars. The X-GitHub-Request-Id request header was used without sanitization as a filesystem path segment for the upload buffer directory, so a traversal value pointed the buffer at an arbitrary path and the deferred cleanup routine recursively removed the traversed target. Exploitation required only network reachability to the instance and no authentication, and it worked even when private mode was enabled. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.21.4, 3.20.6, 3.19.10, 3.18.13 and 3.17.19. This vulnerability was reported via the GitHub Bug Bounty program. Join the discussion | CVE Database V5 | 08/05/2026, 20:05:53 UTC Added: 08/05/2026, 20:26:48 UTC |
CVE-2026-18953: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in AWS aws-transform-mcp-serverCVE-2026-18953 0 Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 might allow a context-dependent actor to write arbitrary files outside the intended working directory via the savePath parameter. To remediate this issue, users should upgrade to version 0.1.5 or later. Join the discussion | CVE Database V5 | 08/05/2026, 19:33:10 UTC Added: 08/05/2026, 19:42:08 UTC |
Showing 1 to 10 of 203 results