Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-36'

View all threats tagged with 'cwe-36'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-36

Threats Tagged 'cwe-36'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-49290: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in byrongamatos slopsmithCVE-2026-49290
0

Slopsmith is a self-contained web application for browsing, playing, and practicing Rocksmith 2014 Custom DLC (CDLC). Prior to 0.2.9-alpha.5, a path-traversal vulnerability in Slopsmith's archive extractors allows an attacker to write arbitrary files outside the extraction directory by supplying a crafted PSARC or sloppak archive. With the default Docker configuration (running as root) and the ability to drop a file into the plugin directory, this escalates to arbitrary remote code execution on the host. Three archive extractors concatenated archive-entry filenames directly onto the extraction root without validation: `lib/psarc.py::unpack_psarc` — PSARC TOC filenames; `lib/patcher.py::unpack_psarc` — duplicate of the above in the patcher flow; `lib/sloppak.py::_unpack_zip` — bare `ZipFile.extractall()` with no member filter. Each accepts entry names containing `..` segments, absolute paths, or backslash separators. The Python `zipfile` module's default `extractall()` is documented as not preventing traversal when callers don't supply a member-filter callback. Version 0.2.9-alpha.5 patches the issue. Until updated, do not open PSARC or sloppak archives from untrusted sources, and do not expose the Slopsmith instance to the public internet. Docker users should also pull the latest image after the next slopsmith Docker image is published.

Join the discussion
CVE-2026-10075: CWE-36 Absolute path traversal in Interinfo DreamMakerCVE-2026-10075
0

DreamMaker developed by Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to read file names under arbitrary path by exploiting an Absolute Path Traversal vulnerability.

Join the discussion
CVE-2026-10044: CWE-36 Absolute Path Traversal in Usagi-org ai-goofish-monitorCVE-2026-10044
0

Usagi-org ai-goofish-monitor contains an unauthenticated arbitrary file read vulnerability in the GET /api/prompts/{filename} endpoint on Windows deployments that allows unauthenticated remote attackers to read arbitrary files by supplying absolute Windows paths or backslash-based traversal sequences. Attackers can bypass the incomplete path traversal guard, which only blocks forward slashes and '..', by providing absolute paths such as Windows system file locations, causing os.path.join to discard the intended prompts directory prefix and expose files accessible to the application process.

Join the discussion
CVE-2026-32997: CWE-36 Absolute Path Traversal in Veeam Backup and ReplicationCVE-2026-32997
0

CVE-2026-32997 is a high-severity vulnerability in Veeam Backup and Replication version 13 that allows an authenticated user with the Backup Administrator role to write arbitrary files on a Linux-based server. This is due to an absolute path traversal issue (CWE-36). The vulnerability does not require user interaction and has a high impact on confidentiality, integrity, and availability. No official patch or remediation guidance is currently provided by the vendor, and no known exploits are reported in the wild.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Tag: cwe-36
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses