path-traversal
Safeguard articles tagged "path-traversal" — guides, analysis, and best practices for software supply chain and application security.
57 articles
Three Kentico Xperience CVEs Chain Into Pre-Auth RCE Through One Component
Two authentication bypasses and a path traversal bug all target Kentico Xperience's Staging Sync Server, chaining into a documented pre-authentication remote code execution path.
JetBrains TeamCity's Path Traversal Bug Is Now Tied to Ransomware
CVE-2024-27199, a relative path traversal in TeamCity enabling limited admin actions, carries CISA's confirmed ransomware flag — a reminder that CI/CD servers are a supply-chain target.
WinRAR, FileZen, and IGEL OS: Three Unrelated Products, Three Broken Trust Boundaries
An APT-linked WinRAR path traversal, a FileZen command injection hiding behind its own antivirus feature, and a Secure Boot bypass in IGEL OS show KEV's reach beyond headline platforms.
The ConnectWise ScreenConnect Path Traversal Bug Behind Storm-1175's Medusa Ransomware Runs
CVE-2024-1708 carries CISA's known-ransomware-use designation, tied directly to Storm-1175's high-tempo Medusa ransomware operations against unpatched, internet-facing RMM instances.
A CVSS 10.0 That Only Reads Files: GitLab CVE-2026-85706
An unauthenticated attacker reads arbitrary files from a GitLab server. There is no code execution, and it still scores 10.0 — because on a source host a read primitive is a credential incident.
Adobe ColdFusion's Path Traversal Bug Reached Full Code Execution
CVE-2026-48282, CVSS 10.0, is a path traversal vulnerability in Adobe ColdFusion that leads directly to arbitrary code execution — the platform's latest entry in a long history of critical CVEs.
Three Maximum-Severity UniFi OS CVEs, Same Day, Same Product
Ubiquiti UniFi OS had three CVSS 10.0 vulnerabilities — command injection, path traversal, and access control failure — all confirmed exploited on the same day in June 2026.
VMware vCenter's Syslog Server Had a Path Traversal Bug CISA Ties to Ransomware
CVE-2026-59310, a directory traversal vulnerability in vCenter's Syslog server leading to code execution, carries CISA's confirmed ransomware campaign flag.
Python tarfile extraction path traversal, the 15-year-old flaw (CVE-2007-4559)
CVE-2007-4559, a path traversal flaw in Python's tarfile module, still lurks in hundreds of thousands of repos. Here's the impact, timeline, and fix.
Django admin ChangeList path traversal (CVE-2021-33203)
CVE-2021-33203 is a staff-only path traversal in Django's admindocs TemplateDetailView. Here's what's affected, its CVSS/EPSS profile, and how to remediate it.
Path traversal vulnerabilities explained with real-world examples
Path traversal (CWE-22) has powered CVEs from Apache to Citrix to F5. Here's how it works, real breaches, and how to stop it.
Is the mammoth npm Package Safe? A DOCX Converter Security Review
The mammoth npm package converts .docx files to HTML, but CVE-2025-11849 showed how a crafted document can read files off your server. Here is what to check.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.