Weaknesses of type CWE-22

5,970 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-73496HIGHMCP Atlassian: Arbitrary server-side file read via attachment uploadEPSS 0.5%CVE-2026-88938HIGHknowns through 0.33.0 Path Traversal via code.find MCP toolEPSS 0.5%CVE-2026-78599MEDIUMStored Path Traversal in Kibana Leading to Unauthorized Deletion of Internal ResourcesEPSS 0.5%CVE-2026-45775MEDIUMDiscourse: Cross-site backup access via path traversal in multisite local backupsEPSS 0.5%CVE-2026-63006MEDIUMZammad: HTML sanitizer API path allowlist bypass via interior path traversal in img src/srcsetEPSS 0.5%CVE-2025-66302MEDIUMGrav vulnerable to Path Traversal allowing server files backupEPSS 0.5%CVE-2026-24147MEDIUMNVIDIA Triton Inference Server contains a vulnerability in triton server where an attacker may cause an information disclosure by uploading EPSS 0.5%CVE-2026-13723MEDIUMDevelar's electron-builder allows arbitrary file overwriteEPSS 0.5%CVE-2026-43732MEDIUMA path handling issue was addressed with improved validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS TahoEPSS 0.5%CVE-2025-12382HIGHPath Traversal Allows Remote Code Execution in AlgoSec Firewall AnalyzerEPSS 0.5%CVE-2026-27884MEDIUMNetExec vulnerable to arbitrary file write via path traversal in spider_plus moduleEPSS 0.5%CVE-2025-14914HIGHIBM WebSphere Application Server Liberty Path TraversalEPSS 0.5%CVE-2026-31886CRITICALDagu has a Path Traversal via `dagRunId` in Inline DAG ExecutionEPSS 0.5%CVE-2026-64826HIGHrConfig < 8.2.13 Path Traversal File Read via FileDownloadControllerEPSS 0.5%CVE-2024-32111MEDIUMWordPress core < 6.5.5 - Auth. Arbitrary .html File Read (Windows Only) vulnerabilityEPSS 0.5%CVE-2026-14783MEDIUMNousResearch hermes-agent skills_tool.py skill_view path traversalEPSS 0.5%CVE-2026-79306MEDIUMCyberPanel v1.9.1 contains a path traversal vulnerability in the compress method exposed through the /filemanager/controller endpoint. An auEPSS 0.5%CVE-2024-45312MEDIUMArbitrary language parameter can passed to `aspell` executable via spelling requests in overleafEPSS 0.5%CVE-2026-11414CRITICALUnauthenticated File Exfiltration in Altium Enterprise Server Vault Service via Hard-coded Cryptographic Key and Path TraversalEPSS 0.5%CVE-2024-8685MEDIUMPath-Traversal vulnerability in Revolution PiEPSS 0.5%