Weaknesses of type CWE-22

5,908 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2025-7098MEDIUMComodo Internet Security Premium File Name path traversalEPSS 0.7%CVE-2026-82428HIGHApache Storm Client: Cross-Tenant Dependency Jar Substitution via Predictable Blob KeysEPSS 0.7%CVE-2024-22231MEDIUMSyndic cache directory creation is vulnerable to a directory traversal attackEPSS 0.7%CVE-2025-14301CRITICALIntegration Opvius AI for WooCommerce <= 1.3.0 - Unauthenticated Arbitrary File Deletion/Read via Path TraversalEPSS 0.7%CVE-2025-39664HIGHPath-Traversal in report schedulerEPSS 0.7%CVE-2026-25891HIGHFiber has an Arbitrary File Read in Static Middleware on WindowsEPSS 0.7%CVE-2024-55602HIGHPenDoc vulnerable to Arbitrary File Read on updating and downloading templates using Path TraversalEPSS 0.7%CVE-2024-9301HIGHA path traversal issue in E2Nest prior to commit 8a41948e553c89c56b14410c6ed395e9cfb9250aEPSS 0.7%CVE-2025-27937HIGHQuick Agent V3 and Quick Agent V2 contain an issue with improper limitation of a pathname to a restricted directory ('Path Traversal'). If eEPSS 0.7%CVE-2024-8410MEDIUMABCD ABCD2 otros_sitios.php path traversalEPSS 0.7%CVE-2026-36762HIGHAn issue in the fileEntityId parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with file upload perEPSS 0.7%CVE-2025-57682MEDIUMDirectory Traversal vulnerability in Papermark 0.20.0 and prior allows authenticated attackers to retrieve arbitrary files from an S3 bucketEPSS 0.7%CVE-2023-37218HIGH Tadiran Telecom Aeonix - CWE-22: Improper Limitation of a Pathname to a Restricted DirectoryEPSS 0.7%CVE-2026-7396MEDIUMNousResearch hermes-agent WeChat Work Platform Adapter wecom.py path traversalEPSS 0.7%CVE-2026-19827MEDIUMalldatacenter alldata logDetailCat Endpoint JobLogController.java FileInputStream path traversalEPSS 0.7%CVE-2026-7271MEDIUMDV0x creative-ad-agent creative-ad-agent-server sdk-server.ts path traversalEPSS 0.7%CVE-2026-81485MEDIUMdanielpopamd linkedin-ads-mcp Media Upload campaign-management.ts fs.readFileSync path traversalEPSS 0.7%CVE-2026-81486MEDIUMbsmi021 mcp-file-context-server Path Resolution index.ts read_context path traversalEPSS 0.7%CVE-2026-5638MEDIUMHerikLyma CPPWebFramework path traversalEPSS 0.7%CVE-2026-16653MEDIUMboazsegev facil.io Public Folder http.c http_sendfile2 path traversalEPSS 0.7%