Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3327

3327 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-40163 Saltcorn has an Unauthenticated Path Traversal in sync endpoints allows arbitrary file write and directory read — saltcorn 8.2 High2026-04-10
CVE-2026-40157 PraisonAI affected by arbitrary file write via path traversal in `praisonai recipe unpack` — PraisonAI 8.1 -2026-04-10
CVE-2026-40086 Rembg has a Path Traversal via Custom Model Loading — rembg 5.3 Medium2026-04-10
CVE-2026-35668 OpenClaw < 2026.3.24 - Sandbox Media Root Bypass via Unnormalized mediaUrl and fileUrl Parameters — OpenClaw 7.7 High2026-04-10
CVE-2026-6057 Unauthenticated Path Traversal in FalkorDB Browser Leads to Remote Code Execution — FalkorDB Browser 9.8 -2026-04-10
CVE-2026-6024 Tenda i6 HTTP R7WebsSecurityHandlerfunction path traversal — i6 7.3 High2026-04-10
CVE-2026-5998 zhayujie chatgpt-on-wechat CowAgent API Memory Content Endpoint service.py dispatch path traversal — chatgpt-on-wechat CowAgent 5.3 Medium2026-04-10
CVE-2026-4351 Perfmatters <= 2.5.9 - Authenticated (Subscriber+) Arbitrary File Overwrite via 'snippets' Parameter — Perfmatters 8.1 High2026-04-10
CVE-2026-40152 PraisonAIAgents has a Path Traversal via Unvalidated Glob Pattern in list_files Bypasses Workspace Boundary — PraisonAIAgents 5.3 Medium2026-04-09
CVE-2026-35206 Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment — helm 3.5AILowAI2026-04-09
CVE-2026-39977 flatpak-builder has a path traversal leading to arbitrary file read on host when installing licence files — flatpak-builder 7.5AIHighAI2026-04-09
CVE-2026-39981 AGiXT has a Path Traversal in safe_join() — AGiXT 8.8 High2026-04-09
CVE-2026-5962 Tenda CH22 httpd R7WebsSecurityHandlerfunction path traversal — CH22 7.3 High2026-04-09
CVE-2026-35204 Helm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory — helm 5.7AIMediumAI2026-04-09
CVE-2026-5849 Tenda i12 HTTP path traversal — i12 7.3 High2026-04-09
CVE-2026-5841 Tenda i3 HTTP R7WebsSecurityHandler path traversal — i3 7.3 High2026-04-09
CVE-2026-40027 ALEAPP NQ Vault Artifact Parser Path Traversal — ALEAPP 7.3 High2026-04-08
CVE-2026-40024 Sleuth Kit tsk_recover Path Traversal — sleuthkit 7.1 High2026-04-08
CVE-2026-5436 MW WP Form <= 5.1.1 - Unauthenticated Arbitrary File Move via regenerate_upload_file_keys — MW WP Form 8.1 High2026-04-08
CVE-2026-39844 NiceGUI has a Path Traversal in NiceGUI Upload Filename on Windows via Backslash Bypass of PurePosixPath Sanitization — nicegui 5.9 Medium2026-04-08
CVE-2026-39859 LiquidJS has a renderFile() / parseFile() bypass configured root and allow arbitrary file read — liquidjs 4.9AIMediumAI2026-04-08
CVE-2026-33466 Improper Limitation of a Pathname to a Restricted Directory in Logstash Leading to Arbitrary File Write — Logstash 8.1 High2026-04-08
CVE-2026-39408 Hono has a path traversal in toSSG() allows writing files outside the output directory — hono 7.5AIHighAI2026-04-08
CVE-2026-39407 Hono has a middleware bypass via repeated slashes in serveStatic — hono 5.3 Medium2026-04-08
CVE-2026-39406 @hono/node-server has a middleware bypass via repeated slashes in serveStatic — node-server 5.3 Medium2026-04-08
CVE-2026-3243 Advanced Members for ACF <= 1.2.5 - Authenticated (Subscriber+) Arbitrary File Deletion via Path Traversal — Advanced Members for ACF 8.8 High2026-04-08
CVE-2026-39847 Emmett has a path traversal in internal assets handler — emmett 9.1 Critical2026-04-07
CVE-2026-34079 Flatpak affected by arbitrary file deletion on the host filesystem — flatpak 7.1AIHighAI2026-04-07
CVE-2026-34371 LibreChat Affected by Arbitrary File Write via `execute_code` Artifact Filename Traversal — LibreChat 6.3 Medium2026-04-07
CVE-2026-39369 WWBN AVideo's GIF poster fetch bypasses traversal scrubbing and exposes local files through public media URLs — AVideo 7.6 High2026-04-07

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3327 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.