The product is vulnerable to file system contents disclosure through path equivalence. Path equivalence involves the use of special characters in file and directory names. The associated manipulations are intended to generate multiple names for the same object.
Volume of CVEs assigned to CWE-41 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-49401HIGH Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.14, Deno's permission system enforces filesystem and execution restrictions by comparing the requested path | Jun 23, 2026 | 8.4 | 32 | NO | NO |
CVE-2026-5816HIGH GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.4 and 18.11 before 18.11.1 that could have allowed an unauthenticated user to execute | Apr 22, 2026 | 8.1 | 29 | NO | NO |
CVE-2023-36396HIGH Windows Compressed Folder Remote Code Execution Vulnerability | Nov 14, 2023 | 7.8 | 28 | NO | NO |
CVE-2026-23674HIGH Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. | Mar 10, 2026 | 7.5 | 26 | NO | NO |
CVE-2025-43298HIGH A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app | Sep 15, 2025 | 7.8 | 25 | NO | NO |
CVE-2025-24470HIGH An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.11 may allow a remote unauthenticated a | Feb 11, 2025 | 8.6 | 24 | NO | NO |
CVE-2025-21332HIGH MapUrlToZone Security Feature Bypass Vulnerability | Jan 14, 2025 | 8.8 | 24 | NO | NO |
CVE-2024-30073HIGH Windows Security Zone Mapping Security Feature Bypass Vulnerability | Sep 10, 2024 | 7.8 | 23 | NO | NO |
CVE-2023-46169MEDIUM
IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow an authenticated user to arbitrarily delete a file. IBM X-Force ID: 269406.
| Mar 7, 2024 | 6.5 | 23 | NO | NO |
CVE-2025-0115MEDIUM A vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated admin on the PAN-OS CLI to read arbitrary files.
The attacker must have network access to the ma | Mar 12, 2025 | 6.8 | 22 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.