Weaknesses of type CWE-22

5,928 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-7400MEDIUMgeekgod382 filesystem-mcp-server read_file_tool/write_file_tool server.py is_path_allowed path traversalEPSS 0.6%CVE-2025-12089MEDIUMData Tables Generator by Supsystic <= 1.10.45 - Authenticated (Admin+) Arbitrary File DeletionEPSS 0.6%CVE-2026-14635MEDIUMkirilkirkov Ecommerce-CodeIgniter-Bootstrap Vendor Multi-Image Endpoint AddProduct.php path traversalEPSS 0.6%CVE-2026-30893CRITICALWazuh cluster sync path traversal in decompress_files() enables arbitrary file write and code execution from authenticated cluster peerEPSS 0.6%CVE-2026-46491HIGHSimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditional deletionEPSS 0.6%CVE-2025-30878HIGHWordPress JS Help Desk plugin <= 2.9.2 - Arbitrary File Deletion vulnerabilityEPSS 0.6%CVE-2024-10100MEDIUMPath Traversal in binary-husky/gpt_academicEPSS 0.6%CVE-2026-41370HIGHOpenClaw < 2026.3.31 - Path Traversal via Inbound Channel Attachment Path in ACP DispatchEPSS 0.6%CVE-2026-48314MEDIUMColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)EPSS 0.6%CVE-2026-62369HIGHKubeEdge: keadm DecompressTarGz path traversal enables arbitrary file write on Windows during edge node joinEPSS 0.6%CVE-2026-52844HIGHCaddy: Windows `file_server` path authorization bypass via encoded backslashEPSS 0.6%CVE-2024-37108HIGHWordPress WishList Member X plugin < 3.26.7 - Authenticated Arbitrary File Deletion vulnerabilityEPSS 0.6%CVE-2024-3107MEDIUMSpectra – WordPress Gutenberg Blocks <= 2.12.6 - Authenticated (Contributor+) Path TraversalEPSS 0.6%CVE-2024-25136HIGHAutomationDirect C-MORE EA9 HMI Path TraversalEPSS 0.6%CVE-2026-86253HIGHh3 before 1.15.6 Path Traversal via Percent-Encoded Dot SegmentsEPSS 0.6%CVE-2024-41726HIGHPath traversal vulnerability exists in SKYSEA Client View Ver.3.013.00 to Ver.19.210.04e. If this vulnerability is exploited, an arbitrary eEPSS 0.6%CVE-2026-23949HIGHjaraco.context Has a Path Traversal VulnerabilityEPSS 0.6%CVE-2024-43996MEDIUMWordPress ElementsKit Pro plugin <= 3.6.0 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2024-37266MEDIUMWordPress Tutor LMS plugin <= 2.7.1 - Path Traversal vulnerabilityEPSS 0.6%CVE-2025-10986MEDIUMPath traversal in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker withEPSS 0.6%