Skip to main content

About CWE-22

Attackers may read files outside the intended directory, overwrite or create files such as programs and libraries, or corrupt critical files. That can expose sensitive data, bypass security mechanisms, crash the product or lead to code execution.

MITRE name
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Abstraction
Base: abstract, but detailed enough to infer detection and prevention methods
Status
Stable
Also known as
Path traversal, Directory traversal, Path transversal

Mitigations

  • +Validate filenames with a strict allowlist of characters, allow at most one dot, and exclude directory separators.
  • +Decode and canonicalize input to the application's internal form before validating it, and avoid decoding the same input twice.
  • +Do not rely on filters that strip dangerous characters, since a filtered result can still form a traversal sequence.
  • +Repeat client-side checks on the server.
  • +Use a list of permitted file extensions to reduce related upload risks.

Detection
Automated static analysis is rated highly effective, though tuning may be needed to deprioritize paths only an administrator controls. Manual code review is also effective when file operations can be assessed in reasonable time.

CWE-22 Vulnerabilities

33 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-104286
Fortinet FortiMail Path Traversal Vulnerability
Fortinet9.82.2%KEV2026-10-01
CVE-2026-93616
Directory Traversal and File upload allows execution of arbitrary script on the Management Server
checkpoint9.819.7%KEV2026-09-22
CVE-2026-85706
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
GitLab10.093.0%KEV2026-09-12
CVE-2026-66384
Authenticated users may write data outside the intended Docker cache path
jfrog5.30.7%KEV2026-08-12
CVE-2026-59310
vCenter directory-traversal vulnerability
VMware9.82.6%KEV2026-07-30
CVE-2026-48282
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Adobe10.042.4%KEV2026-06-30
CVE-2026-34909
Ubiquiti UniFi OS Path Traversal Vulnerability
Ubiquiti Inc10.01.8%KEV2026-05-22
CVE-2024-1708
Improper limitation of a pathname to a restricted directory (“path traversal”)
ConnectWise8.495.4%KEV2024-02-21
CVE-2024-7399
Samsung MagicINFO 9 Server Path Traversal Vulnerability
Samsung Electronics8.891.9%KEV2024-08-09
CVE-2025-2749
Kentico Xperience <= 13.0.178 Staging Media File Upload Authenticated RCE
Kentico7.24.1%KEV2025-03-24
CVE-2025-8110
File overwrite in file update API in Gogs
Gogs8.785.2%KEV2025-12-10
CVE-2025-6218
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability
RARLAB7.890.5%KEV2025-06-21
CVE-2021-43798
Grafana path traversal
grafana7.588.5%KEV2021-12-07
CVE-2019-5418
Rails Ruby on Rails Path Traversal Vulnerability
Rails7.598.5%KEV2019-03-27
CVE-2024-0769
D-Link DIR-859 HTTP POST Request hedwig.cgi path traversal
D-Link5.382.7%KEV2024-01-21
CVE-2025-4632
Samsung MagicINFO 9 Server Path Traversal Vulnerability
Samsung Electronics9.824.3%KEV2025-05-13
CVE-2025-34028
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
Commvault9.397.6%KEV2025-04-22
CVE-2024-4885
WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability
Progress Software Corporation9.899.3%KEV2024-06-25
CVE-2024-11667
Zyxel Multiple Firewalls Path Traversal Vulnerability
Zyxel7.52.9%KEV2024-11-27
CVE-2024-8963
Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability
Ivanti9.498.6%KEV2024-09-19
CVE-2024-7262
Arbitrary Code Execution in WPS Office
Kingsoft9.32.9%KEV2024-08-15
CVE-2024-32113
Apache OFBiz: Path traversal leading to RCE
Apache Software Foundation9.199.9%KEV2024-05-08
CVE-2024-28995
SolarWinds Serv-U L Directory Transversal Vulnerability
SolarWinds8.699.6%KEV2024-06-06
CVE-2023-32315
Openfire administration console authentication bypass
igniterealtime8.6100.0%KEV2023-05-26
CVE-2022-41328
Fortinet FortiOS Path Traversal Vulnerability
Fortinet6.510.7%KEV2023-03-07
CVE-2014-0780
InduSoft Web Studio Path Traversal
InduSoft9.874.7%KEV2014-04-25
CVE-2019-7483
SonicWall SMA100 Directory Traversal Vulnerability
SonicWall7.54.0%KEV2019-12-19
CVE-2020-1631
Out of Cycle Security Advisory: Junos OS: Security vulnerability in J-Web and web based (HTTP/HTTPS) services
Juniper Networks8.84.8%KEV2020-05-04
CVE-2021-41773
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
Apache Software Foundation7.5100.0%KEV2021-10-05
CVE-2021-42013
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
Apache Software Foundation9.8100.0%KEV2021-10-07
CVE-2021-20023
SonicWall Email Security Path Traversal Vulnerability
SonicWall4.951.7%KEV2021-04-20
CVE-2026-1056
Snow Monkey Forms <= 12.0.3 - Unauthenticated Arbitrary File Deletion via Path Traversal
inc27349.813.5%2026-01-28
CVE-2026-22218
Chainlit < 2.9.4 Arbitrary File Read via /project/element
Chainlit7.19.5%2026-01-19

Frequently Asked Questions

What is CWE-22?→

CWE-22 is MITRE's entry for path traversal. Outside input builds a file path that escapes the directory it was supposed to stay within.

Which child entries should be considered instead of CWE-22?→

MITRE suggests CWE-23 for relative path traversal and CWE-36 for absolute path traversal when the details are known.

How many exploited vulnerabilities are classified as CWE-22?→

This database lists 33 CVE records mapped to CWE-22 by their CVE Numbering Authority. 31 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 6 to known ransomware campaigns. Examples include CVE-2026-104286, CVE-2026-93616, CVE-2026-85706.

Sources

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.