Absolute Path Traversal (CWE-36)
CWE-36 occurs when outside input is used to build a path that should stay within a restricted directory, but absolute path sequences are not neutralized. A full path supplied by the user resolves outside that directory. MITRE lists it as a suggested child of CWE-22.
About CWE-36
Attackers may read sensitive files, create or overwrite programs and libraries, bypass security mechanisms that rely on files, or corrupt files to cause a crash.
Mitigations
- +Validate filenames with a strict allowlist and exclude directory separators.
- +Decode and canonicalize input before validation and avoid decoding twice.
- +Do not rely on filters that remove dangerous characters, since alternate separators may remain.
- +Use an application firewall as an interim measure when the code cannot be fixed.
Detection
Automated static analysis (SAST) is rated highly effective for this weakness.
CWE-36 Vulnerabilities
5 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2024-48248 | NAKIVO Backup and Replication Absolute Path Traversal Vulnerability | NAKIVO | 8.6 | 94.4% | KEV | 2025-03-04 |
| CVE-2024-13159 | Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability | Ivanti | 9.8 | 100.0% | KEV | 2025-01-14 |
| CVE-2024-13160 | Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability | Ivanti | 9.8 | 91.2% | KEV | 2025-01-14 |
| CVE-2024-13161 | Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability | Ivanti | 9.8 | 90.1% | KEV | 2025-01-14 |
| CVE-2018-20250 | WinRAR Absolute Path Traversal Vulnerability | Check Point Software Technologies Ltd. | 7.8 | 96.0% | KEV | 2019-02-05 |
Most Affected Vendors
Related Weaknesses
Tool Categories That Address This Weakness
Frequently Asked Questions
What is CWE-36?→
CWE-36 is absolute path traversal: user input supplies a full path that points outside the directory the application meant to use.
How does CWE-36 differ from CWE-23?→
MITRE lists CWE-36 for absolute paths and CWE-23 for relative path traversal, both as children to consider under CWE-22.
How many exploited vulnerabilities are classified as CWE-36?→
This database lists 5 CVE records mapped to CWE-36 by their CVE Numbering Authority. 5 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 1 to known ransomware campaigns. Examples include CVE-2024-48248, CVE-2024-13159, CVE-2024-13160.
Sources
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.