Weaknesses of type CWE-22

5,964 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-69086HIGHSiYuan before v3.7.3 Path Traversal via unvalidated avIDEPSS 0.5%CVE-2025-7641HIGHAssistant for NextGEN Gallery <= 1.0.9 - Unauthenticated Arbitrary Directory DeletionEPSS 0.5%CVE-2023-34342MEDIUMAMI BMC contains a vulnerability in the IPMI handler, where an attacker can upload and download arbitrary files under certain circumstances,EPSS 0.5%CVE-2024-37268HIGHWordPress Striking theme <= 2.3.4 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2025-58591MEDIUMPath TraversalEPSS 0.5%CVE-2026-33748HIGHBuildKit Git URL subdir component can cause access to restricted filesEPSS 0.5%CVE-2026-57119HIGHPraisonAI: Unauthenticated Local File Inclusion via agent_file path in the Jobs APIEPSS 0.5%CVE-2026-54650HIGHopenhole-server vulnerable to path traversal via URL-decoded request pathEPSS 0.5%CVE-2025-58590MEDIUMPath traversalEPSS 0.5%CVE-2026-64963LOWPath Traversal in ATutorEPSS 0.5%CVE-2026-55760HIGHhandlebars.java FileTemplateLoader Path TraversalEPSS 0.5%CVE-2026-57129HIGHPraisonAI: Arbitrary File Read via `@file:` Mention Path TraversalEPSS 0.5%CVE-2026-73646HIGHPostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File DisclosureEPSS 0.5%CVE-2026-52797HIGHGogs: Overwriting critical files results in a denial of serviceEPSS 0.5%CVE-2026-75859HIGHCodeWhale before 0.8.64 Arbitrary File Read via instructionsEPSS 0.5%CVE-2025-30594MEDIUMWordPress Include URL plugin <= 0.3.5 Arbitrary File Download VulnerabilityEPSS 0.5%CVE-2026-55390HIGHArbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gateEPSS 0.5%CVE-2026-77271HIGHMCP Atlassian: Incomplete path traversal fix allows intra-CWD module overwrite and RCE (bypass of CVE-2026-27825)EPSS 0.5%CVE-2026-0846HIGHArbitrary File Read via Absolute Path Input in nltk.util.filestring()EPSS 0.5%CVE-2026-3585HIGHThe Events Calendar <= 6.15.17 - Authenticated (Author+) Arbitrary File Read via ajax_create_importEPSS 0.5%