The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '\..\filename' (leading backslash dot dot) sequences that can resolve to a location that is outside of that directory.
Volume of CVEs assigned to CWE-29 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
63 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-6909HIGH Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2. | Dec 18, 2023 | 7.5 | 79 | NO | YES |
CVE-2023-1177CRITICAL Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1.
| Mar 24, 2023 | 9.8 | 79 | NO | YES |
CVE-2024-6396CRITICAL A vulnerability in the `_backup_run` function in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any file on the host server and exfiltrate arbitrary data. The vul | Jul 12, 2024 | 9.8 | 68 | NO | YES |
CVE-2024-3848HIGH A path traversal vulnerability exists in mlflow/mlflow version 2.11.0, identified as a bypass for the previously addressed CVE-2023-6909. The vulnerability arises from the applicat | May 16, 2024 | 7.5 | 55 | NO | YES |
CVE-2023-6021HIGH LFI in Ray's log API endpoint allows attackers to read any file on the server without authentication. The issue is fixed in version 2.8.1+. Ray maintainers' response can be found h | Nov 16, 2023 | 7.5 | 54 | NO | YES |
CVE-2024-4322HIGH A path traversal vulnerability exists in the parisneo/lollms-webui application, specifically within the `/list_personalities` endpoint. By manipulating the `category` parameter, an | May 16, 2024 | 7.5 | 48 | NO | YES |
CVE-2024-4320CRITICAL A remote code execution (RCE) vulnerability exists in the '/install_extension' endpoint of the parisneo/lollms-webui application, specifically within the `@router.post("/install_ex | Jun 6, 2024 | 9.8 | 46 | NO | NO |
CVE-2023-2780CRITICAL Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.3.1. | May 17, 2023 | 9.8 | 46 | NO | YES |
CVE-2024-2083CRITICAL A directory traversal vulnerability exists in the zenml-io/zenml repository, specifically within the /api/v1/steps endpoint. Attackers can exploit this vulnerability by manipulatin | Apr 16, 2024 | 9.9 | 44 | NO | NO |
CVE-2024-3429CRITICAL A path traversal vulnerability exists in the parisneo/lollms application, specifically within the `sanitize_path_from_endpoint` and `sanitize_path` functions in `lollms_core\lollms | Jun 6, 2024 | 9.8 | 41 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.