← Vulnerability feed

Vulnerability record · CVE-2021-41323 · published 30 September 2021

CVE-2021-41323: Pydio cells path traversal vulnerability

Pydio · Cells

Directory traversal in the Compress feature in Pydio Cells 2.2.9 allows remote authenticated users to overwrite personal files, or Cells files belonging to any user, via the format parameter.

6.5 CVSS 3.1 Medium EPSS 2.1% · top 19.2% CWE-22 · Path traversal
6.5CVSS 3.1 base score, v2 4.0
2.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Directory traversal in the Compress feature in Pydio Cells 2.2.9 allows remote authenticated users to overwrite personal files, or Cells files belonging to any user, via the format parameter.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-41323 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-32749Pydio cells incorrect authorization vulnerabilityPydio Cells allows users by default to create so-called external users in order to share files with them. By modifying the HTTP request sent when cre…EPSS 14%8.8CVE-2019-12901Pydio cells path traversal vulnerabilityPydio Cells before 1.5.0 fails to neutralize '../' elements, allowing an attacker with minimum privilege to Upload files to, and Delete files/folders…EPSS 1.7%8.1CVE-2020-12851Pydio cells path traversal vulnerabilityPydio Cells 2.0.4 allows an authenticated user to write or overwrite existing files in another user’s personal and cells folders (repositories) by up…EPSS 1.5%7.2CVE-2020-12847Pydio cells vulnerabilityPydio Cells 2.0.4 web application offers an administrative console named “Cells Console” that is available to users with an administrator role. This …EPSS 1.7%7.0CVE-2020-12850Pydio cells improper privilege management vulnerabilityThe following vulnerability applies only to the Pydio Cells Enterprise OVF version 2.0.4. Prior versions of the Pydio Cells Enterprise OVF (such as v…EPSS 0.49%6.8CVE-2020-12852Pydio cells improper input validation vulnerabilityThe update feature for Pydio Cells 2.0.4 allows an administrator user to set a custom update URL and the public RSA key used to validate the download…EPSS 2.4%6.5CVE-2023-32750Pydio cells server-side request forgery (ssrf) vulnerabilityPydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which are run in the background. Th…EPSS 3.8%6.5CVE-2021-41324Pydio cells path traversal vulnerabilityDirectory traversal in the Copy, Move, and Delete features in Pydio Cells 2.2.9 allows remote authenticated users to enumerate personal files (or Cel…EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2021-41323), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.