Safeguard
Tag

path-traversal

Safeguard articles tagged "path-traversal" — guides, analysis, and best practices for software supply chain and application security.

57 articles

Vulnerability Analysis

Three Kentico Xperience CVEs Chain Into Pre-Auth RCE Through One Component

Two authentication bypasses and a path traversal bug all target Kentico Xperience's Staging Sync Server, chaining into a documented pre-authentication remote code execution path.

Sep 16, 20265 min read
Vulnerability Analysis

JetBrains TeamCity's Path Traversal Bug Is Now Tied to Ransomware

CVE-2024-27199, a relative path traversal in TeamCity enabling limited admin actions, carries CISA's confirmed ransomware flag — a reminder that CI/CD servers are a supply-chain target.

Sep 16, 20265 min read
Vulnerability Analysis

WinRAR, FileZen, and IGEL OS: Three Unrelated Products, Three Broken Trust Boundaries

An APT-linked WinRAR path traversal, a FileZen command injection hiding behind its own antivirus feature, and a Secure Boot bypass in IGEL OS show KEV's reach beyond headline platforms.

Sep 16, 20265 min read
Vulnerability Analysis

The ConnectWise ScreenConnect Path Traversal Bug Behind Storm-1175's Medusa Ransomware Runs

CVE-2024-1708 carries CISA's known-ransomware-use designation, tied directly to Storm-1175's high-tempo Medusa ransomware operations against unpatched, internet-facing RMM instances.

Sep 16, 20265 min read
Vulnerability Analysis

A CVSS 10.0 That Only Reads Files: GitLab CVE-2026-85706

An unauthenticated attacker reads arbitrary files from a GitLab server. There is no code execution, and it still scores 10.0 — because on a source host a read primitive is a credential incident.

Sep 16, 20266 min read
Vulnerability Analysis

Adobe ColdFusion's Path Traversal Bug Reached Full Code Execution

CVE-2026-48282, CVSS 10.0, is a path traversal vulnerability in Adobe ColdFusion that leads directly to arbitrary code execution — the platform's latest entry in a long history of critical CVEs.

Sep 16, 20264 min read
Vulnerability Analysis

Three Maximum-Severity UniFi OS CVEs, Same Day, Same Product

Ubiquiti UniFi OS had three CVSS 10.0 vulnerabilities — command injection, path traversal, and access control failure — all confirmed exploited on the same day in June 2026.

Sep 16, 20264 min read
Vulnerability Analysis

VMware vCenter's Syslog Server Had a Path Traversal Bug CISA Ties to Ransomware

CVE-2026-59310, a directory traversal vulnerability in vCenter's Syslog server leading to code execution, carries CISA's confirmed ransomware campaign flag.

Sep 16, 20264 min read
Vulnerability Analysis

Python tarfile extraction path traversal, the 15-year-old flaw (CVE-2007-4559)

CVE-2007-4559, a path traversal flaw in Python's tarfile module, still lurks in hundreds of thousands of repos. Here's the impact, timeline, and fix.

Aug 9, 20268 min read
Vulnerability Analysis

Django admin ChangeList path traversal (CVE-2021-33203)

CVE-2021-33203 is a staff-only path traversal in Django's admindocs TemplateDetailView. Here's what's affected, its CVSS/EPSS profile, and how to remediate it.

Aug 8, 20267 min read
Vulnerability Analysis

Path traversal vulnerabilities explained with real-world examples

Path traversal (CWE-22) has powered CVEs from Apache to Citrix to F5. Here's how it works, real breaches, and how to stop it.

Aug 4, 20266 min read
Open Source

Is the mammoth npm Package Safe? A DOCX Converter Security Review

The mammoth npm package converts .docx files to HTML, but CVE-2025-11849 showed how a crafted document can read files off your server. Here is what to check.

Jul 29, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.