Weaknesses of type CWE-22

5,950 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-26065CRITICALcalibre: Path Traversal can Lead to Arbitrary File Write and Potential Code ExecutionEPSS 0.6%CVE-2026-78602MEDIUMImproper Limitation of a Pathname to a Restricted Directory in Elastic Maps Server Leading to Unauthorized File DisclosureEPSS 0.6%CVE-2024-49285HIGHWordPress SSV MailChimp plugin <= 3.1.5 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2026-15331MEDIUMzhayujie CowAgent Skill Installation service.py _add_package path traversalEPSS 0.6%CVE-2026-32938CRITICALSiYuan has an Arbitrary File Read in its Desktop Publish ServiceEPSS 0.6%CVE-2026-46581HIGHIn Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, aEPSS 0.6%CVE-2026-44716HIGHPipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File Read via `%2F`-Encoded SeparatorEPSS 0.6%CVE-2024-39036MEDIUMSeaCMS v12.9 is vulnerable to Arbitrary File Read via admin_safe.php.EPSS 0.6%CVE-2026-49009LOWNorthern.tech Mender Server v4.1.0, v4.0.1 and below, and fixed in v4.1.1 and v4.0.2 allows Directory Traversal.EPSS 0.6%CVE-2025-47211MEDIUMQTS, QuTS heroEPSS 0.6%CVE-2024-6789HIGHPath traversal in M-Files APIEPSS 0.6%CVE-2025-0703MEDIUMJoeyBling bootplus SysFileController.java path traversalEPSS 0.6%CVE-2023-25606MEDIUMAn improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-23] in FortiAnalyzer and FortiManager mEPSS 0.6%CVE-2025-68476HIGHKEDA has Arbitrary File Read via Insufficient Path Validation in HashiCorp Vault Service Account CredentialEPSS 0.6%CVE-2023-23366HIGHMusic StationEPSS 0.6%CVE-2026-58170HIGHVibe-Trading < 0.1.10 - Path Traversal in Proposal Identifier Allows Forging Live Trading MandatesEPSS 0.6%CVE-2023-23365HIGHMusic StationEPSS 0.6%CVE-2026-56122HIGHWinstone Servlet Engine 0.9.10 Path Traversal via HTTP Request PathsEPSS 0.6%CVE-2026-84421HIGHDataStage on Cloud Pak for Data has several vulnerabilitiesEPSS 0.6%CVE-2023-4990HIGHDirectory traversal vulnerability in MCL-Net versions prior to 4.6 Update Package (P01) may allow attackers to read arbitrary files.EPSS 0.6%