CWE Top 25 Most Dangerous Software Weaknesses (2024)
CWE Top 25 2024: Access Control and Authorization

CWE Top 25 Most Dangerous Software Weaknesses (2024) CWE-22: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)

Rank 5 in the 2024 CWE Top 25 (frequency x severity of CVEs). Path Traversal: user input used in a file path is not properly neutralised, allowing access to files and directories outside the intended location.

Other controls in CWE Top 25 2024: Access Control and Authorization

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.