Weaknesses of type CWE-22

5,908 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-81560MEDIUMblackms aistack Static File server.ts path traversalEPSS 0.7%CVE-2024-5852MEDIUMWordPress File Upload <= 4.24.7 - Authenticated (Contributor+) Directory TraversalEPSS 0.7%CVE-2025-12960MEDIUMSimple CSV Table <= 1.0.1 - Directory Traversal to Authenticated (Contributor+) Arbitrary File ReadEPSS 0.7%CVE-2026-36726MEDIUMAn arbitrary file deletion vulnerability in the /api/delete-temp-license/{file} endpoint of bookcars v8.3 allows unauthenticated attackers tEPSS 0.7%CVE-2022-3940LOWlanyulei ferry task.go path traversalEPSS 0.7%CVE-2024-51998HIGHPath traversal using file URI scheme without supplying hostname in changedetection.ioEPSS 0.7%CVE-2026-15990HIGHFormidable Charts <= 2.0.1 - Unauthenticated Arbitrary File Read via 'frm_graph' ParameterEPSS 0.7%CVE-2024-7744MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Progress WS_FTP ServerEPSS 0.7%CVE-2026-54670CRITICALWeGIA: Unauthenticated Auth Bypass + Local File InclusionEPSS 0.7%CVE-2026-101067MEDIUMdbgate save-uploaded-file Endpoint files.js saveUploadedFile path traversalEPSS 0.7%CVE-2026-101066MEDIUMdbgate Archive Link Creation archive.js createLink path traversalEPSS 0.7%CVE-2024-44195HIGHA logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.1. An app may be able to read arbitrary files.EPSS 0.7%CVE-2026-63490HIGHHandlebars.java: Arbitrary file read in `SpringTemplateLoader` via URL-fragment suffix bypassEPSS 0.7%CVE-2026-85661CRITICALexcel-mcp-server 0.1.8 Arbitrary File Read/Write via stdio modeEPSS 0.7%CVE-2026-55607HIGHClaude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code ExecutionEPSS 0.7%CVE-2024-51751MEDIUMArbitrary file read with File and UploadButton components in GradioEPSS 0.7%CVE-2026-50180HIGHLangroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file readEPSS 0.7%CVE-2026-53872HIGHpicklescan - Arbitrary File Read via Unsafe Pickle DeserializationEPSS 0.7%CVE-2024-37043MEDIUMQTS, QuTS heroEPSS 0.7%CVE-2024-37046LOWQTS, QuTS heroEPSS 0.7%