Threadlinqs IntelligenceStart free

Weakness · VariantCWE-35

CWE-35: Path Traversal: '.../...//'

KEV-linkedVariant

As of 2026-10-05, CWE-35 (Path Traversal: '.../...//') underlies 3 CVEs tracked by Threadlinqs, 1 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 14 tracked threats.

CVEs
3Mapped to CWE-35
CISA KEV
1Exploited in the wild
Critical
1CVSS v3 critical CVEs
Threats
14Tracked campaigns citing it
Likelihood
—MITRE likelihood of exploit

Last updated:

What is CWE-35?

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.

CWE-35 is a variant-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific.

Source: MITRE CWE (CWE-35 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Confidentiality, Integrity — Read Files or Directories, Modify Files or Directories, Bypass Protection Mechanism. Not properly neutralizing '.../...//' (doubled triple dot slash) allows attackers to traverse the file system to access files or directories that are outside of the restricted directory.

Source: MITRE CWE, common consequences.

How CWE-35 is exploited in the wild

Threadlinqs maps 3 CVEs to CWE-35, published between 2025-08-08 and 2026-06-09. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 1 critical, 1 high, 1 medium. The highest EPSS score in the set is 7.0% (CVE-2025-8088), the modelled probability of exploitation in the next 30 days. 14 tracked threats reference CWE-35 directly or through a CVE it covers; the most recent is “GitLab Patches Max-Severity Unauthenticated Path Traversal Flaw in Repository Commits API (CVE-2026-85706, CVSS 10.0)” (2026-09-11). Affected products concentrate in Microsoft (2), Dtsearch (1), Rarlab (1), among 4 vendors in total.

Vulnerabilities (CVEs)

All 3 CVEs mapped to CWE-35, CISA KEV first, then by CVSS score.

  • CVE-2025-8088 — CISA KEV · CVSS 8.8 high · EPSS 7.0% · published 2025-08-08
  • CVE-2026-40128 — CVSS 9 critical · EPSS 0.4% · published 2026-06-09
  • CVE-2026-26124 — CVSS 6.7 medium · EPSS 0.1% · published 2026-03-05

Affected vendors

Threat activity

14 tracked threats cite CWE-35:

Mitigations

  • Implementation / Input Validation: Assume all input is malicious. Use an "accept known good" input validation strategy, i.e., use a list of acceptable inputs that strictly conform to specifications. Reject any input that does not strictly conform to specifications, or transform it into something that does. When performing input validation, consider all potentially relevant properties, including length, type of input, the full range of acceptable values, missing or extra inputs, syntax, consistency across related fields, and conformance to business rules. As an example of business rule logic, "boat" may be syntactically valid because it only contains alphanumeric characters, but it is not valid if the input is only expected…
  • Implementation / Input Validation: Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous inputs after they have been checked.

Source: MITRE CWE, potential mitigations.

Detection methods (MITRE CWE)

  • Automated Static Analysis: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.