Weaknesses of type CWE-22

5,883 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2025-69194HIGHWget2: arbitrary file write via metalink path traversal in gnu wget2EPSS 0.8%CVE-2023-34645HIGHjfinal CMS 5.1.0 has an arbitrary file read vulnerability.EPSS 0.8%CVE-2022-23447HIGHAn improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiExtender management interfaEPSS 0.8%CVE-2023-26820HIGHsiteproxy v1.0 was discovered to contain a path traversal vulnerability via the component index.js.EPSS 0.8%CVE-2026-9102CRITICALPath Traversal in Altium Enterprise Server ComparisonService Allows Arbitrary File WriteEPSS 0.8%CVE-2024-36814MEDIUMAn arbitrary file read vulnerability in Adguard Home before v0.107.52 allows authenticated attackers to access arbitrary files as root on thEPSS 0.8%CVE-2024-41310HIGHAndServer 2.1.12 is vulnerable to Directory Traversal.EPSS 0.8%CVE-2022-47747HIGHkraken <= 0.1.4 has an arbitrary file read vulnerability via the component testfs.EPSS 0.8%CVE-2023-28163MEDIUMWhen downloading files through the Save As dialog on Windows with suggested filenames containing environment variable names, Windows would hEPSS 0.8%CVE-2024-24591HIGHA path traversal vulnerability in versions 1.4.0 to 1.14.1 of the client SDK of Allegro AI’s ClearML platform enables a maliciously uploadedEPSS 0.8%CVE-2023-46346HIGHIn the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 4.1.1 from MyPrestaModules for PrestaShop, aEPSS 0.8%CVE-2026-64679HIGHAtlantis: Path Traversal in Atlantis Workspace Handling Allows Out-of-Bounds Directory Deletion/CreationEPSS 0.8%CVE-2023-29200MEDIUMcontao/core-bundle has path traversal vulnerability in the file managerEPSS 0.8%CVE-2026-64824CRITICALHome Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restoreEPSS 0.8%CVE-2026-40526HIGHVolmarg Personal Management System Path Traversal via get-file EndpointEPSS 0.8%CVE-2025-2193MEDIUMMRCMS org.marker.mushroom.controller.FileController delete.do delete path traversalEPSS 0.8%CVE-2024-8898MEDIUMPath Traversal in parisneo/lollms-webuiEPSS 0.8%CVE-2026-29220MEDIUMApache OFBiz: Low-Privilege LFI in Content ComponentEPSS 0.8%CVE-2024-54004MEDIUMJenkins Filesystem List Parameter Plugin 0.0.14 and earlier does not restrict the path used for the File system objects list Parameter, alloEPSS 0.8%CVE-2019-25352HIGHGenivia Crystal Live HTTP Server 6.01 - 'Crystal Live HTTP Server' Path TraversalEPSS 0.8%