CWE-27: Path Traversal: 'dir/../../filename'
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize multiple internal "../" sequences that can resolve to a location that is outside of that directory.
24 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-51747 — Arbitrary File Read and Delete in kanboard
- CVE-2025-66518 — Apache Kyuubi: Unauthorized directory access due to missing path normalization
- CVE-2025-58761 — Tautulli vulnerable to Unauthenticated Path Traversal in `real_pms_image_proxy`
- CVE-2024-24809 — Traccar vulnerable to Path Traversal: 'dir/../../filename' and Unrestricted Upload of File with Dangerous Type
- CVE-2026-24457 — An unsafe parsing of OpenMQ's configuration, allows a remote attacker to read arbitrary files from a MQ Broker's server.
- CVE-2024-43658 — Using the <redacted> action or <redacted>.sh script, arbitrary files and directories can be deleted using directory traversal.
- CVE-2025-10438 — Path Traversal in Yordam BT's Yordam Katalog
- CVE-2026-62391 — Apache Kyuubi: kyuubi.session.local.dir.allow.list bypass via unprefixed Spark file-conf aliases
- CVE-2026-76344 — Path Traversal through the Search Dispatch REST API in Splunk Enterprise
- CVE-2026-20018 — Cisco Firepower Management Center Software and Firepower Threat Defense Path Traversal Vulnerability
- CVE-2025-58292 — Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect av
Recently published
- CVE-2026-76344 — Path Traversal through the Search Dispatch REST API in Splunk Enterprise
- CVE-2026-62391 — Apache Kyuubi: kyuubi.session.local.dir.allow.list bypass via unprefixed Spark file-conf aliases
- CVE-2026-24457 — An unsafe parsing of OpenMQ's configuration, allows a remote attacker to read arbitrary files from a MQ Broker's server.
- CVE-2026-20018 — Cisco Firepower Management Center Software and Firepower Threat Defense Path Traversal Vulnerability
- CVE-2025-66518 — Apache Kyuubi: Unauthorized directory access due to missing path normalization
- CVE-2025-58292 — Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect av
- CVE-2025-10438 — Path Traversal in Yordam BT's Yordam Katalog
- CVE-2025-58761 — Tautulli vulnerable to Unauthenticated Path Traversal in `real_pms_image_proxy`
- CVE-2024-43658 — Using the <redacted> action or <redacted>.sh script, arbitrary files and directories can be deleted using directory traversal.
- CVE-2024-51747 — Arbitrary File Read and Delete in kanboard
- CVE-2024-24809 — Traccar vulnerable to Path Traversal: 'dir/../../filename' and Unrestricted Upload of File with Dangerous Type