Weaknesses of type CWE-22

5,866 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-23907MEDIUMApache PDFBox Examples: Path Traversal in PDFBox ExtractEmbeddedFiles Example CodeEPSS 0.9%CVE-2025-46783CRITICALPath traversal vulnerability exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If this vulnerability is exploited, arbitEPSS 0.9%CVE-2026-35485HIGHtext-generation-webui has a Path Traversal in load_grammar() — arbitrary file read without authenticationEPSS 0.9%CVE-2022-23522HIGHArbitrary File Write when Extracting Tarballs retrieved from a remote location using in mindsdbEPSS 0.9%CVE-2020-7495—A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability during zip file extraction exists in EPSS 0.9%CVE-2020-7529—A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Transversal') vulnerability exists in SCADAPack 7x Remote ConnecEPSS 0.9%CVE-2025-59709MEDIUMAn issue was discovered in Biztalk360 through 11.5. because of mishandling of user-provided input in a path to be read by the server, a SupeEPSS 0.9%CVE-2023-30548MEDIUMPath traversal vulnerability in gatsby-plugin-sharpEPSS 0.9%CVE-2024-45189MEDIUMMage AI git content request remote arbitrary file leakEPSS 0.9%CVE-2026-3695MEDIUMSourceCodester Modern Image Gallery App delete.php path traversalEPSS 0.9%CVE-2026-61445CRITICALPraisonAI before 4.6.78 Arbitrary File Write and Command ExecutionEPSS 0.9%CVE-2024-45188MEDIUMMage AI file content request remote arbitrary file leakEPSS 0.9%CVE-2024-7551MEDIUMjuzaweb CMS Theme Editor default path traversalEPSS 0.9%CVE-2024-27121HIGHPath traversal vulnerability exists in Machine Automation Controller NJ Series and Machine Automation Controller NX Series. An arbitrary filEPSS 0.9%CVE-2019-25577MEDIUMSeoToaster Ecommerce 3.0.0 Local File Inclusion via backend_themeEPSS 0.9%CVE-2026-27819HIGHVikunja has Path Traversal in CLI RestoreEPSS 0.9%CVE-2026-50203CRITICALApache Airflow SFTP provider: Path traversal in SFTPHook.retrieve_directory allows local file write outside the destination directory via malicious server-supplied directory-entry namesEPSS 0.9%CVE-2024-8704HIGHAdvanced File Manager <= 5.2.8 - Authenticated (Administrator+) Local JavaScript File Inclusion via fma_localeEPSS 0.9%CVE-2024-46648HIGHeNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via scan_folder.EPSS 0.9%CVE-2024-46645HIGHeNMS 4.0.0 is vulnerable to Directory Traversal via get_tree_files.EPSS 0.9%