Weaknesses of type CWE-22

5,927 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2022-4594MEDIUMdrogatkin TJWS2 WarRoller.java deployWar path traversalEPSS 0.6%CVE-2025-5741MEDIUMCWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file EPSS 0.6%CVE-2026-82393HIGHpnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on installEPSS 0.6%CVE-2022-46902MEDIUMAn issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is a Path Traversal for an Unzip operation. The VoceEPSS 0.6%CVE-2024-44167HIGHThis issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, EPSS 0.6%CVE-2024-52444HIGHWordPress Opal Woo Custom Product Variation plugin <= 1.1.3 - Arbitrary File Deletion vulnerabilityEPSS 0.6%CVE-2023-49058LOWDirectory Traversal vulnerability in SAP Master Data GovernanceEPSS 0.6%CVE-2023-42456LOWsudo-rs Session File Relative Path Traversal vulnerabilityEPSS 0.6%CVE-2023-37476MEDIUMZip slip in OpenRefineEPSS 0.6%CVE-2026-50757HIGHDirectory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary code via the nex-ai-draEPSS 0.6%CVE-2025-23250HIGHNVIDIA NeMo Framework contains a vulnerability where an attacker could cause an improper limitation of a pathname to a restricted directory EPSS 0.6%CVE-2026-56233HIGHCapgo - SSRF and Privilege Escalation via Path Traversal in Builder Upload ProxyEPSS 0.6%CVE-2026-4222MEDIUMSSCMS download PathUtils.RemoveParentPath path traversalEPSS 0.6%CVE-2023-49089HIGHUmbraco CMS possible path traversal when creating packages from backofficeEPSS 0.6%CVE-2026-33670CRITICALSiYuan has directory traversal within its publishing serviceEPSS 0.6%CVE-2025-23422HIGHWordPress Store Locator plugin <= 3.98.10 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2026-4044MEDIUMprojectsend Delete import-orphans.php realpath path traversalEPSS 0.6%CVE-2025-6070MEDIUMRestrict File Access <= 1.1.2 - Authenticated (Subscriber+) Arbitrary File ReadEPSS 0.6%CVE-2025-58072HIGHImproper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:EPSS 0.6%CVE-2025-56815HIGHDatart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses MultipartFile.transfEPSS 0.6%