Weaknesses of type CWE-22

5,969 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-49133HIGHTypemill < 2.24.0 Path Traversal via ControllerApiImage::getPagemedia()EPSS 0.5%CVE-2026-28078MEDIUMWordPress uListing plugin <= 2.2.0 - Arbitrary File Download vulnerabilityEPSS 0.5%CVE-2026-79773MEDIUMWinter CMS before 1.2.13 Local File Inclusion via JavaScriptEPSS 0.5%CVE-2024-25123HIGHPath Manipulation in file mslib/index.py in MSSEPSS 0.5%CVE-2025-43537LOWA path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2.EPSS 0.5%CVE-2025-25800MEDIUMSeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe_file.php.EPSS 0.5%CVE-2026-56394HIGHCraft CMS - Authenticated Path Traversal in assets/icon Extension ParameterEPSS 0.5%CVE-2026-73225HIGHelecterm: Path traversal in FTP/SFTP recursive folder download via unsanitized server filenameEPSS 0.5%CVE-2025-7975HIGHAnritsu ShockLine CHX File Parsing Directory Traversal Remote Code Execution VulnerabilityEPSS 0.5%CVE-2025-7359HIGHCounter live visitors for WooCommerce <= 1.3.6 - Unauthenticated Arbitrary File Deletion in wcvisitor_get_blockEPSS 0.5%CVE-2026-52868HIGHOFFIS DCMTK Toolkit Path TraversalEPSS 0.5%CVE-2026-72903HIGHTabby: Windows SFTP path traversal allows a malicious server to write files outside the selected download directoryEPSS 0.5%CVE-2026-73223HIGHelecterm: Path traversal in editWithSystemEditor temp file path via unsanitized SFTP filenameEPSS 0.5%CVE-2026-73227HIGHelecterm's RDP clipboard file download may parse unsafe file nameEPSS 0.5%CVE-2026-54591HIGHAsyncSSH: SCP Path Traversal to Arbitrary File WriteEPSS 0.5%CVE-2026-33529LOWZoraxy: Authenticated Path Traversal in Config Import leads to RCEEPSS 0.5%CVE-2026-54520HIGHAI Agent Automation: Workflow file step path traversal allows read and write outside the expected directoryEPSS 0.5%CVE-2026-41491HIGHDapr: Service Invocation path traversal ACL bypassEPSS 0.5%CVE-2026-32055HIGHOpenClaw < 2026.2.26 - Workspace Path Boundary Bypass via Non-existent SymlinkEPSS 0.5%CVE-2022-23970HIGHASUS RT-AX56U - Path TraversalEPSS 0.5%