Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3323

3323 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-39307 PraisonAI has an Arbitrary File Write (Zip Slip) in Templates Extraction — PraisonAI 8.1 High2026-04-07
CVE-2026-39308 PraisonAI recipe registry publish path traversal allows out-of-root file write — PraisonAI 7.1 High2026-04-07
CVE-2026-39306 PraisonAI recipe registry pull path traversal writes files outside the chosen output directory — PraisonAI 7.3 High2026-04-07
CVE-2026-39305 Arbitrary File Write / Path Traversal in Action Orchestrator — PraisonAI 9.0 Critical2026-04-07
CVE-2026-35615 PraisonAI has a Path Traversal in FileTools — PraisonAI 8.1AIHighAI2026-04-07
CVE-2026-35613 Path traversal in coursevault-preview due to improper base-directory boundary validation — coursevault-preview 5.1 Medium2026-04-07
CVE-2026-35605 File Browser has an access rule bypass via HasPrefix without trailing separator in path matching — filebrowser 7.3AIHighAI2026-04-07
CVE-2026-35592 pyLoad has an Incomplete Tar Path Traversal Fix in UnTar._safe_extractall via os.path.commonprefix Bypass — pyload 5.3 Medium2026-04-07
CVE-2026-35583 Emissary has a Path Traversal via Blacklist Bypass in Configuration API — emissary 5.3 Medium2026-04-07
CVE-2026-35492 Kedro-Datasets has a path traversal vulnerability in PartitionedDataset allows arbitrary file write — kedro-plugins 6.5 Medium2026-04-07
CVE-2026-35487 text-generation-webui has a Path Traversal in load_prompt() — .txt file read without authentication — text-generation-webui 5.3 Medium2026-04-07
CVE-2026-35485 text-generation-webui has a Path Traversal in load_grammar() — arbitrary file read without authentication — text-generation-webui 7.5 High2026-04-07
CVE-2026-35484 text-generation-webui has a Path Traversal in load_preset() — .yaml file read without authentication — text-generation-webui 5.3 Medium2026-04-07
CVE-2026-35483 text-generation-webui has a Path Traversal in load_template() — .jinja/.yaml/.yml file read without authentication — text-generation-webui 5.3 Medium2026-04-07
CVE-2026-33227 Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ: Improper Limitation of a Pathname to a Restricted Classpath Directory — Apache ActiveMQ Client 6.5AIMediumAI2026-04-07
CVE-2026-35454 Code Extension Marketplace has a Zip Slip Path Traversal — code-marketplace 6.2AIMediumAI2026-04-06
CVE-2026-35471 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs — goshs 9.1AICriticalAI2026-04-06
CVE-2026-35393 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload — goshs 9.8AICriticalAI2026-04-06
CVE-2026-35392 goshs has an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload — goshs 9.1AICriticalAI2026-04-06
CVE-2026-35177 Path traversal issue with zip.vim in Vim — vim 4.1 Medium2026-04-06
CVE-2026-35174 Chyrp Lite has a Path Traversal to Remote Code Execution — chyrp-lite 9.1 Critical2026-04-06
CVE-2026-35167 Kedro has a path traversal in versioned dataset loading via unsanitized version string — kedro 7.1 High2026-04-06
CVE-2026-35050 text-generation-webui affected by Remote Code Execution (RCE) through Path Traversal at "Session -> Save extention settings to user_data/settings.yaml". — text-generation-webui 9.1 Critical2026-04-06
CVE-2026-34783 Ferret has a Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites — ferret 8.1 High2026-04-06
CVE-2026-5638 HerikLyma CPPWebFramework path traversal — CPPWebFramework 5.3 Medium2026-04-06
CVE-2026-5597 griptape-ai griptape ComputerTool tool.py path traversal — griptape 6.3 Medium2026-04-05
CVE-2019-25687 Pegasus CMS 1.0 Remote Code Execution via extra_fields.php — Pegasus CMS 9.8 Critical2026-04-05
CVE-2019-25671 VA MAX 8.3.4 Remote Code Execution via changeip.php — VA MAX 8.8 High2026-04-05
CVE-2026-5595 griptape-ai griptape FileManagerTool save_memory_artifacts_to_disk path traversal — griptape 6.3 Medium2026-04-05
CVE-2026-5535 FedML-AI FedML MQTT Message FileUtils.java path traversal — FedML 4.3 Medium2026-04-05

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3323 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.