Weaknesses of type CWE-22

5,950 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2025-33035HIGHFile Station 5EPSS 0.5%CVE-2026-17081HIGHIBM Db2 Mirror for i is affected by multiple vulnerabilitiesEPSS 0.5%CVE-2026-57331CRITICALWordPress Paid Videochat Turnkey Site plugin <= 7.4.8 - Arbitrary File Deletion vulnerabilityEPSS 0.5%CVE-2024-47563MEDIUMA vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate aEPSS 0.5%CVE-2026-23644HIGHesm.sh has path traversal in `extractPackageTarball` that enables file writes from malicious packagesEPSS 0.5%CVE-2026-55389HIGHdatamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`EPSS 0.5%CVE-2023-3331—Improper Limitation of a Pathname to a Restricted Directory vulnerability in NEC Corporation Aterm Aterm WG2600HP2, WG2600HP, WG2200HP, WG18EPSS 0.5%CVE-2025-27785HIGHApplio allows arbitrary file read in train.py export_index functionEPSS 0.5%CVE-2025-24961MEDIUMInsecure path traversal in filesystem and filesystem-nio2 storage backends in org.gaul S3ProxyEPSS 0.5%CVE-2026-74038HIGHWazuh 4.0.0 < 4.14.6 Path Traversal DoS via Agent EnrollmentEPSS 0.5%CVE-2026-53940HIGHConda: Entry-point path traversal in noarch:python install (arbitrary file write) — canonical Python implementationEPSS 0.5%CVE-2024-46954HIGHAn issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ..EPSS 0.5%CVE-2026-33027MEDIUMNginx UI: Improper Path Validation Allows Recursive Deletion of the Nginx Configuration DirectoryEPSS 0.5%CVE-2024-43797MEDIUMPath Traversal in audiobookshelfEPSS 0.5%CVE-2026-82111MEDIUMiswalle getnote-mcp upload_image index.ts fs.readFileSync path traversalEPSS 0.5%CVE-2026-7182CRITICALPath Traversal in DiagramEPSS 0.5%CVE-2026-40611HIGHLego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 ProviderEPSS 0.5%CVE-2026-6320HIGHSalon Booking System – Free Version <= 10.30.25 - Unauthenticated Arbitrary File Read via Booking File Field Path TraversalEPSS 0.5%CVE-2026-67185HIGHTinyWeb 0.0.8 Path Traversal via URL Path ComponentEPSS 0.5%CVE-2025-27786HIGHApplio allows arbitrary file removal in core.pyEPSS 0.5%