Weaknesses of type CWE-22

5,970 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-23633MEDIUMGogs has arbitrary file read/write via path traversal in Git hook editingEPSS 0.5%CVE-2025-32209MEDIUMWordPress Total processing card payments for WooCommerce Plugin <= 7.1.5 - Arbitrary File Download vulnerabilityEPSS 0.5%CVE-2024-54169MEDIUMIBM EntireX path traversalEPSS 0.5%CVE-2026-65695HIGHOffice-Word-MCP-Server 1.1.11 Path Traversal via document toolsEPSS 0.5%CVE-2024-2210MEDIUMThe Plus Addons for Elementor <= 5.4.1 - Authenticated (Contributor+) Local File Inclusion via Team Member ListingEPSS 0.5%CVE-2025-10283CRITICALImproper .git Sanitization in gitdumper Enables RCEEPSS 0.5%CVE-2026-59149MEDIUMMockoon: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)EPSS 0.5%CVE-2026-59221HIGHopen-webui terminal proxy path traversal guard bypass via 9x encoded traversalEPSS 0.5%CVE-2024-47351HIGHWordPress MaxSlider plugin <= 1.2.3 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2026-27442CRITICALzip_attachments Path TraversalEPSS 0.5%CVE-2023-41888MEDIUMPhishing through a login page malicious URL in GLPIEPSS 0.5%CVE-2018-25144HIGHMicrohard Systems IPn4G 1.1.0 Arbitrary File Access via Undocumented System EditorEPSS 0.5%CVE-2026-73496HIGHMCP Atlassian: Arbitrary server-side file read via attachment uploadEPSS 0.5%CVE-2024-45074MEDIUMIBM webMethods Integration directory traversalEPSS 0.5%CVE-2026-44594HIGHesm.sh: Path Traversal via package.json browser field allows reading arbitrary server filesEPSS 0.5%CVE-2026-11944MEDIUMopenSIS Classic 9.3 - Authenticated path traversal in SentMail attachment downloadEPSS 0.5%CVE-2026-88938HIGHknowns through 0.33.0 Path Traversal via code.find MCP toolEPSS 0.5%CVE-2026-81030HIGHMage AI through 0.9.79 Arbitrary File Read via Unvalidated Path in browser_items EndpointEPSS 0.5%CVE-2026-85618HIGHConvertX 0.17.0 Arbitrary File Read via LaTeX Input DirectivesEPSS 0.5%CVE-2024-49771MEDIUMMPXJ has a Potential Path Traversal VulnerabilityEPSS 0.5%