CWE-36: Absolute Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as "/abs/path" that can resolve to a location that is outside of that directory.
137 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-48248 — NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /
- CVE-2025-57790 — Path Traversal Vulnerability
- CVE-2024-51549 — Absolute Path Traversal
- CVE-2025-0851 — Path traversal issue in Deep Java Library
- CVE-2024-9924 — Hgiga OAKlouds - Arbitrary File Read And Delete
- CVE-2024-10811 — Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
- CVE-2024-47883 — Butterfly has path/URL confusion in resource handling leading to multiple weaknesses
- CVE-2024-10833 — Arbitrary File Write in eosphoros-ai/db-gpt
- CVE-2024-10831 — Arbitrary File Write through Absolute Path Traversal in eosphoros-ai/db-gpt
- CVE-2026-1330 — HAMASTAR Technology|MeetingHub - Arbitrary File Read
- CVE-2025-8912 — WellChoose|Organization Portal System - Arbitrary File Reading through Path Traversal
- CVE-2025-15227 — WELLTEND TECHNOLOGY| BPMFlowWebkit - Arbitrary File Read
- CVE-2025-34392 — Barracuda RMM < 2025.1.1 Service Center Absolute Path Traversal RCE
- CVE-2024-13945 — Stored Absolute Path Traversal
- CVE-2025-46822 — Unauthenticated Arbitrary File Read via Absolute Path
- CVE-2025-68472 — MindsDB has improper sanitation of filepath that leads to information disclosure and DOS
- CVE-2025-13282 — Chunghwa Telecom|TenderDocTransfer - Arbitrary File Delete
- CVE-2024-12646 — Chunghwa Telecom topm-client - Arbitrary File Delete
- CVE-2024-12643 — Chunghwa Telecom tbm-client - Arbitrary File Delete
- CVE-2025-36357 — IBM Planning Analytics Local Directory Traversal
Recently published
- CVE-2026-47630 — NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path travers
- CVE-2026-47606 — NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path travers
- CVE-2026-46345 — compliance-trestle - jinja has an Arbitrary File Write via Path Traversal
- CVE-2026-47243 — Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs
- CVE-2026-54202 — TeamDavid: Path Traversal in the archive creation functionality
- CVE-2026-61891 — In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoin
- CVE-2026-13346 — pip absolute path traversal during download from malicious package indexes
- CVE-2026-13189 — SpellChecker DictionaryLanguage Path Traversal Vulnerability in Telerik UI for ASP.NET AJAX
- CVE-2026-57211 — RabbitMQ: UNC SSRF affecting the management UI on Windows
- CVE-2026-15302 — ARMember <= 4.0.27 - Directory Traversal via X-FILENAME
- CVE-2026-49290 — Slopsmith has path traversal in archive extractors that allows arbitrary file write → potential RCE
- CVE-2026-53698 — Silverpeas through 6.4.6 mishandles the "Personal space" feature that is selected when no componentId is set.
- CVE-2026-10075 — Interinfo|DreamMaker - Path Traversal
- CVE-2026-10044 — ai-goofish-monitor Unauthenticated Arbitrary File Read via GET /api/prompts/
- CVE-2026-32997 — A vulnerability allowing an authenticated user with the Backup Administrator role to write arbitrary files on Linux-base
- CVE-2026-4782 — Avada Builder <= 3.15.2 - Authenticated (Subscriber+) Arbitrary File Read via 'custom_svg' Shortcode Parameter
- CVE-2026-42315 — pyLoad: Path Traversal via Package Folder Name in set_package_data
- CVE-2026-6418 — PaperCut NG/MF: Path Traversal in Shared Account Synchronization
- CVE-2026-44029 — An issue was discovered in Nix before 2.34.7. Writing to arbitrary files can occur via "nix-prefetch-url --unpack" or "n
- CVE-2026-7217 — Deepractice PromptX Document File index.ts read_pdf absolute path traversal