What is CWE-23?
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
CWE-23 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Not Language-Specific; Not Technology-Specific; Web Based; AI/ML.
Source: MITRE CWE (CWE-23 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Integrity, Confidentiality, Availability — Execute Unauthorized Code or Commands. The attacker may be able to create or overwrite critical files that are used to execute code, such as programs or libraries.
- Integrity — Modify Files or Directories. The attacker may be able to overwrite or create critical files, such as programs, libraries, or important data. If the targeted file is used for a security mechanism, then the attacker may be able to bypass that mechanism. For example, appending a new account at the end of a password file may allow an attacker to bypass authentication.
- Confidentiality — Read Files or Directories. The attacker may be able read the contents of unexpected files and expose sensitive data by traversing the file system to access files or directories that are outside of the restricted directory. If the targeted file is used for a security mechanism, then the attacker may be able to bypass that mechanism. For example, by reading a password file, the attacker could conduct brute force password guessing attacks in order to break into an account on the system.
- Availability — DoS: Crash, Exit, or Restart. The attacker may be able to overwrite, delete, or corrupt unexpected critical files such as programs, libraries, or important data. This may prevent the product from working at all and in the case of a protection mechanisms such as authentication, it has the potential to lockout every user of the product.
Source: MITRE CWE, common consequences.
How CWE-23 is exploited in the wild
Threadlinqs maps 8 CVEs to CWE-23, published between 2024-03-04 and 2026-09-08. 2 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 1 is tied to ransomware campaigns. By CVSS v3 severity the set splits into 2 critical, 3 high, 1 medium. The highest EPSS score in the set is 89.5% (CVE-2025-64446), the modelled probability of exploitation in the next 30 days. 7 tracked threats reference CWE-23 directly or through a CVE it covers; the most recent is “Gogs Critical RCE via Path Traversal in Organization Names (CVE-2026-52813)” (2026-08-20). Affected products concentrate in Canonical (1), Fortinet (1), Jetbrains (1), among 8 vendors in total.
Vulnerabilities (CVEs)
All 8 CVEs mapped to CWE-23, CISA KEV first, then by CVSS score.
- CVE-2025-64446 — CISA KEV · CVSS 9.4 critical · EPSS 89.5% · published 2025-11-14
- CVE-2026-34926 — CISA KEV · CVSS 6.7 medium · EPSS 0.7% · published 2026-05-21
- CVE-2026-52813 — CVSS 10 critical · EPSS 0.9% · published 2026-06-24
- CVE-2026-8023 — CVSS 7.5 high · EPSS 0.6% · published 2026-06-29
- CVE-2024-27199 — CVSS 7.3 high · EPSS 82.4% · published 2024-03-04
- CVE-2026-81838 — CVSS 7.1 high · EPSS 0.1% · published 2026-08-27
- CVE-2026-47680 — EPSS 0.3% · published 2026-09-08
- CVE-2026-77113 — EPSS 0.1% · published 2026-08-20
Affected vendors
- Canonical — 1 CVE
- Fortinet — 1 CVE
- Jetbrains — 1 CVE
- Trend Micro, Inc. — 1 CVE
- aws — 1 CVE
- fluxcd — 1 CVE
- gogs — 1 CVE
- zephyrproject — 1 CVE
Threat activity
7 tracked threats cite CWE-23:
- Gogs Critical RCE via Path Traversal in Organization Names (CVE-2026-52813)CRITICAL
- ChocoPoC RAT Campaign Uses Malicious PoC-Exploit Python Packages to Backdoor Security ResearchersHIGH
- ChatGPT File Download Flow Path Traversal / Local File Inclusion (LFI) via Guardrail Bypass Social EngineeringMEDIUM
- ChocoPoC Campaign: Trojanised PoC Exploits and PyPI Packages Deliver Python RAT Using Mapbox Datasets API as Dead-Drop C2HIGH
- ChocoPoC: Python RAT Distributed via Trojanized PoC Exploits Targeting Security ResearchersHIGH
- CISA KEV (2026-05-21): CVE-2025-34291 Langflow CORS Token Hijack-to-RCE & CVE-2026-34926 Trend Micro Apex One On-Premise Directory TraversalCRITICAL
- Storm-1175 Medusa Ransomware Zero-Day Exploitation Campaign (CVE-2026-23760, CVE-2025-10035)CRITICAL
Mitigations
- Implementation / Input Validation: Assume all input is malicious. Use an "accept known good" input validation strategy, i.e., use a list of acceptable inputs that strictly conform to specifications. Reject any input that does not strictly conform to specifications, or transform it into something that does. When performing input validation, consider all potentially relevant properties, including length, type of input, the full range of acceptable values, missing or extra inputs, syntax, consistency across related fields, and conformance to business rules. As an example of business rule logic, "boat" may be syntactically valid
- Implementation / Input Validation: Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous inputs after they have been checked. Use a built-in path canonicalization function (such as realpath() in C) that produces the canonical version of the pathname, which effectively removes ".." sequences and symbolic links (CWE-23, CWE-59). This includes: - realpath() in C - getCanonicalPath(
- Operation / Firewall: Use an application firewall that can detect attacks against this weakness. It can be beneficial in cases in which the code cannot be fixed (because it is controlled by a third party), as an emergency prevention measure while more comprehensive software assurance measures are applied, or to provide defense in depth [REF-1481].
Source: MITRE CWE, potential mitigations.
Detection methods (MITRE CWE)
- Automated Static Analysis: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)
Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.