CWE-36Base5 in KEV

Absolute Path Traversal

Draft in the CWE catalog · 133 CVEs mapped

133
CVEs mapped
5
In KEV
7.2
Median CVSS
What it is

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as "/abs/path" that can resolve to a location that is outside of that directory.

Recent examples
5.5cvss
CVE-2026-47630

CVE-2026-47630 - MEDIUM Severity Vulnerability

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution.

MEDIUMno explanation yet
0%
epss
6.5cvss
CVE-2026-47606

CVE-2026-47606 - MEDIUM Severity Vulnerability

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution and information disclosure.

MEDIUMno explanation yet
0%
epss
8.4cvss
CVE-2026-46345

CVE-2026-46345 - HIGH Severity Vulnerability

compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the `-o/--output` argument in `trestle author jinja` allows writing files outside the intended workspace. The application does not properly validate, `../`, `..\`, or absolute paths. This allows arbitrary file write to attacker-controlled locations. Versions 3.12.3 and 4.0.3 patch the issue.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-36
Abstraction
Base
Structure
Simple
Status
Draft
References (2)