Weaknesses of type CWE-22

5,970 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-39307HIGHPraisonAI has an Arbitrary File Write (Zip Slip) in Templates ExtractionEPSS 0.5%CVE-2026-18899HIGHLangflow is affected by multiple authentication bypass, path traversal, authorization, and server-side request forgery vulnerabilitiesEPSS 0.5%CVE-2026-41887MEDIUMFlarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)EPSS 0.5%CVE-2025-51463HIGHPath Traversal in restore_run_backup() in AIM 3.28.0 allows remote attackers to write arbitrary files to the server's filesystem via a craftEPSS 0.5%CVE-2025-3547MEDIUMfrdel Agent-Zero get_work_dir_files path traversalEPSS 0.5%CVE-2026-59924MEDIUMMistune: Arbitrary File Read via Include directive path traversalEPSS 0.5%CVE-2026-32808HIGHpyLoad: Arbitrary File Deletion via Path Traversal during Encrypted 7z Password VerificationEPSS 0.5%CVE-2025-14753HIGHIBM Cloud Pak for Data is vulnerable to path traversalEPSS 0.5%CVE-2024-35081HIGHLuckyFrameWeb v3.5.2 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter in the fileDownload methoEPSS 0.5%CVE-2025-53358MEDIUMkotaemon Vulnerable to Path Traversal via Link UploadEPSS 0.5%CVE-2023-54403HIGHYonyou U8 CRM Arbitrary File Read via getemaildata.phpEPSS 0.5%CVE-2026-5203MEDIUMCMS Made Simple UserGuide Module XML Import class.UserGuideImporterExporter.php _copyFilesToFolder path traversalEPSS 0.5%CVE-2026-44566HIGHOpen WebUI: Arbitrary File Upload and Path TraversalEPSS 0.5%CVE-2026-15700MEDIUMDedeCMS Album Publishing Feature zip.class.php ExtractFile path traversalEPSS 0.5%CVE-2026-6957HIGHPath traversal in Mattermost Legal Hold plugin via unsanitized file name from federated peer allows arbitrary file write.EPSS 0.5%CVE-2026-23888MEDIUMpnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip)EPSS 0.5%CVE-2026-34603HIGH@tinacms/graphql's Media Endpoints Can Escape the Media Root via Symlinks or JunctionsEPSS 0.5%CVE-2025-11016MEDIUMkalcaddle kodbox index.class.php fileOut path traversalEPSS 0.5%CVE-2023-41290MEDIUMQuFirewallEPSS 0.5%CVE-2026-54910HIGHFileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary filesEPSS 0.5%