Weaknesses of type CWE-22

5,950 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-55117HIGHA malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Access Application to access files EPSS 0.6%CVE-2026-73760MEDIUMAuthenticated Path Traversal Vulnerability Leads to Remote Unauthorized Access to Files in AOS-CXEPSS 0.6%CVE-2026-8183HIGHLangflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcementEPSS 0.6%CVE-2026-81730HIGHDolibarr 9.0.0 through 23.0.4 Path Traversal via EmailCollector Attachment FilenameEPSS 0.6%CVE-2026-3345MEDIUMPath Traversal and Arbitrary File Write Vulnerability in IBM Langflow Desktop API v2 File Upload EndpointEPSS 0.6%CVE-2026-63445HIGHPerses: Unvalidated project parameter enables filesystem path traversalEPSS 0.6%CVE-2026-21227HIGHAzure Logic Apps Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2026-7667HIGHPath Traversal Vulnerability in API Request Component Content-Disposition Header ProcessingEPSS 0.6%CVE-2026-8859CRITICALPath Traversal in APIRequest Component via Content-Disposition HeaderEPSS 0.6%CVE-2022-4493MEDIUMscifio ZIP File DefaultSampleFilesService.java downloadAndUnpackResource path traversalEPSS 0.6%CVE-2025-14728MEDIUMRapid7 Velociraptor Directory Traversal VulnerabilityEPSS 0.6%CVE-2025-29787HIGHzip Vulnerable to Incorrect Path Canonicalization During Archive Extraction, Leading to Arbitrary File WriteEPSS 0.6%CVE-2024-33557HIGHWordPress XStore Core plugin <= 5.3.8 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2026-79318MEDIUMweb2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) is vulnerable to Directory Traversal in read_file()/write_file() (applEPSS 0.6%CVE-2024-9146MEDIUMWordPress CSS JS Files plugin <= 1.5.0 - Directory Traversal to File Read vulnerabilityEPSS 0.6%CVE-2023-25305HIGHPolyMC Launcher <= 1.4.3 is vulnerable to Directory Traversal. A mrpack file can be maliciously crafted to create arbitrary files outside ofEPSS 0.6%CVE-2025-53110HIGHModel Context Protocol Servers Vulnerable to Path Validation Bypass via Colliding Path PrefixEPSS 0.6%CVE-2026-40383HIGHJoomla! Core - [20260509] - LFI in HTMLView layout parameterEPSS 0.6%CVE-2024-35712MEDIUMWordPress Database Cleaner: Clean, Optimize & Repair plugin <= 1.0.5 - Arbitrary File Read vulnerabilityEPSS 0.6%CVE-2026-88940MEDIUMknowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpointEPSS 0.6%