Skip to content
Noroxi

CWE-22 · 9,994 records

Path traversal

Why does it happen?

A user-supplied file name is joined with the allowed directory, but the result is never checked to confirm it is still inside that directory.

Vulnerable and fixed code

A representative teaching example. Highlighted lines mark where the bug and the fix are.

Vulnerable

ts
const file = path.join(ROOT, req.query.name);res.sendFile(file);

Fixed

ts
const file = path.resolve(ROOT, req.query.name);if (!file.startsWith(ROOT + path.sep)) {  return res.sendStatus(400);}res.sendFile(file);

How to prevent it

  1. 01After resolving the path, verify it stays within the root directory.
  2. 02Serve files by database ID rather than by name.
  3. 03Run the server process with read access only to the directories it needs.

CVEs in this class

10,000 records

  • In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attack

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    ivanti · connect secureMay 8, 2019

  • Certain WSO2 products allow unrestricted file upload with resultant remote code execution.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    wso2 · api managerApr 18, 2022

  • The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    vmware · cloud foundationSep 23, 2021

  • In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Inte

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    f5 · big-ip access policy managerJul 1, 2020

  • Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character follo

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    jenkins · jenkinsJan 24, 2024

  • An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    citrix · application delivery controller firmwareDec 27, 2019

  • An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    fortinet · fortiproxyJun 4, 2019

  • Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    apache · http serverOct 5, 2021

  • A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <=

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    buffalo · wsr-2533dhpl2-bk firmwareApr 29, 2021

  • Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    apache · http serverOct 7, 2021

  • Apache OFBiz: Path traversal leading to RCE

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    apache · ofbizMay 8, 2024

  • The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.1

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    atlassian · confluence serverMar 25, 2019

  • The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    vmware · cloud foundationFeb 24, 2021

  • Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to re

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    adobe · coldfusionAug 11, 2010

  • WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    progress · whatsup goldJun 25, 2024

  • Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a c

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    nazgul · nostromo nhttpdOct 14, 2019

  • In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat we

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    sysaid · sysaidNov 10, 2023

  • An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0.

    CriticalCVSS 9.8KEVWeaponizedEPSS 95%

    synacor · zimbra collaboration suiteSep 25, 2022

  • Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attack

    CriticalCVSS 9.8KEVWeaponizedEPSS 92%

    samsung · magicinfo 9 serverAug 12, 2024

  • Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it.

    CriticalCVSS 9.8KEVWeaponizedEPSS 92%

    synacor · zimbra collaboration suiteAug 12, 2022

  • Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab

    CriticalCVSS 10.0KEVWeaponizedEPSS 91%

    gitlab · gitlabSep 11, 2026

  • Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.

    CriticalCVSS 9.1KEVWeaponizedEPSS 99%

    ivanti · endpoint manager cloud services applianceSep 19, 2024

  • Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal

    CriticalCVSS 9.3KEVWeaponizedEPSS 98%

    commvault · commvaultApr 22, 2025

  • This external control of file name or path vulnerability allows remote attackers to access or modify system files.

    CriticalCVSS 9.8KEVWeaponizedEPSS 90%

    qnap · photo stationDec 5, 2019

  • A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenti

    CriticalCVSS 9.1KEVWeaponizedEPSS 98%

    mitel · micollabOct 21, 2024

All vulnerability classes