CWE-26: Path Traversal: '/dir/../filename'
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize "/dir/../filename" sequences that can resolve to a location that is outside of that directory.
13 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-25575 — NavigaTUM has a Path Traversal Vulnerability in the propose_edits functionality
- CVE-2025-25295 — Label Studio has a Path Traversal Vulnerability via image Field
- CVE-2025-53908 — RomM vulnerable to Authenticated Path Traversal
- CVE-2026-42196 — django-s3file: Relative path traversal
- CVE-2024-5865 — Arbitrary File Reading in Centrify PAS
- CVE-2026-76317 — Path Traversal through the Lookup Configuration REST API in Splunk Enterprise
- CVE-2024-5866 — Arbitrary Directory Listing in Centrify PAS
- CVE-2026-46747 — A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application does not p
Recently published
- CVE-2026-76317 — Path Traversal through the Lookup Configuration REST API in Splunk Enterprise
- CVE-2026-46747 — A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application does not p
- CVE-2026-42196 — django-s3file: Relative path traversal
- CVE-2026-25575 — NavigaTUM has a Path Traversal Vulnerability in the propose_edits functionality
- CVE-2025-53908 — RomM vulnerable to Authenticated Path Traversal
- CVE-2025-25295 — Label Studio has a Path Traversal Vulnerability via image Field
- CVE-2024-5866 — Arbitrary Directory Listing in Centrify PAS
- CVE-2024-5865 — Arbitrary File Reading in Centrify PAS