Skip to main content

About CWE-36

Attackers may read sensitive files, create or overwrite programs and libraries, bypass security mechanisms that rely on files, or corrupt files to cause a crash.

MITRE name
Absolute Path Traversal
Abstraction
Base: abstract, but detailed enough to infer detection and prevention methods
Status
Draft

Mitigations

  • +Validate filenames with a strict allowlist and exclude directory separators.
  • +Decode and canonicalize input before validation and avoid decoding twice.
  • +Do not rely on filters that remove dangerous characters, since alternate separators may remain.
  • +Use an application firewall as an interim measure when the code cannot be fixed.

Detection
Automated static analysis (SAST) is rated highly effective for this weakness.

CWE-36 Vulnerabilities

5 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2024-48248
NAKIVO Backup and Replication Absolute Path Traversal Vulnerability
NAKIVO8.694.4%KEV2025-03-04
CVE-2024-13159
Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
Ivanti9.8100.0%KEV2025-01-14
CVE-2024-13160
Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
Ivanti9.891.2%KEV2025-01-14
CVE-2024-13161
Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
Ivanti9.890.1%KEV2025-01-14
CVE-2018-20250
WinRAR Absolute Path Traversal Vulnerability
Check Point Software Technologies Ltd.7.896.0%KEV2019-02-05

Most Affected Vendors

Related Weaknesses

Frequently Asked Questions

What is CWE-36?→

CWE-36 is absolute path traversal: user input supplies a full path that points outside the directory the application meant to use.

How does CWE-36 differ from CWE-23?→

MITRE lists CWE-36 for absolute paths and CWE-23 for relative path traversal, both as children to consider under CWE-22.

How many exploited vulnerabilities are classified as CWE-36?→

This database lists 5 CVE records mapped to CWE-36 by their CVE Numbering Authority. 5 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 1 to known ransomware campaigns. Examples include CVE-2024-48248, CVE-2024-13159, CVE-2024-13160.

Sources

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.