Weaknesses of type CWE-22

5,882 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2022-4511MEDIUMRainyGao DocSys path traversalEPSS 0.8%CVE-2026-44615MEDIUMPath traversal in NotebookRepo note and folder path compositionEPSS 0.8%CVE-2026-39861HIGHClaude Code: Sandbox Escape via Symlink Following Allows Arbitrary File Write Outside WorkspaceEPSS 0.8%CVE-2025-10050MEDIUMDeveloper Loggers for Simple History <= 0.5 - Authenticated (Admin+) Local File InclusionEPSS 0.8%CVE-2025-6755HIGHGame Users Share Buttons <= 1.3.0 - Authenticated (Subscriber+) Arbitrary File Deletion via themeNameId ParameterEPSS 0.8%CVE-2024-36418HIGHSuiteCRM authenticated RCE using connectorsEPSS 0.8%CVE-2024-21876CRITICALUnauthenticated Path Traversal via URL Parameter in Enphase IQ Gateway version < 8.2.4225EPSS 0.8%CVE-2024-0380MEDIUMWP Recipe Maker <= 9.1.0 - Directory TraversalEPSS 0.8%CVE-2025-11631MEDIUMRainyGao DocSys deleteDoc.do path traversalEPSS 0.8%CVE-2026-30283CRITICALAn arbitrary file overwrite vulnerability in PEAKSEL D.O.O. NIS Animal Sounds and Ringtones v1.3.0 allows attackers to overwrite critical inEPSS 0.8%CVE-2024-5353MEDIUManji-plus AJ-Report ZIP File decompress path traversalEPSS 0.8%CVE-2025-12824HIGHPlayer Leaderboard 1.0.0 - 1.0.2 - Authenticated (Contributor+) Local File InclusionEPSS 0.8%CVE-2024-26150HIGH`@backstage/backend-common` vulnerable to path traversal through symlinksEPSS 0.8%CVE-2018-25184MEDIUMSurreal ToDo 0.6.1.2 Local File Inclusion via index.phpEPSS 0.8%CVE-2025-8516MEDIUMKingdee Cloud-Starry-Sky Enterprise Edition IIS-K3CloudMiniApp FileUploadAction.class path traversalEPSS 0.8%CVE-2025-53906MEDIUMVim has path traversal issue with zip.vim and special crafted zip archivesEPSS 0.8%CVE-2021-27916HIGHRelative Path Traversal / Arbitrary File Deletion in Mautic (GrapesJS Builder)EPSS 0.8%CVE-2023-52288HIGHAn issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a GET reEPSS 0.8%CVE-2026-29870HIGHA directory traversal vulnerability in the agentic-context-engine project versions up to 0.7.1 allows arbitrary file writes via the checkpoiEPSS 0.8%CVE-2026-44885MEDIUMPortainer: Path traversal in backup archive extraction allows arbitrary file writeEPSS 0.8%