Weaknesses of type CWE-22

5,972 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2025-10449HIGHPath Traversal in Saysis Computer Systems' Saysis Web PortalEPSS 0.4%CVE-2025-14413HIGHSoda PDF Desktop CBZ File Parsing Directory Traversal Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-37145MEDIUMAuthenticated Arbitrary File Download Vulnerabilities in a Low-Level Interface Library Affecting AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management InterfaceEPSS 0.4%CVE-2026-25766MEDIUMEcho has a Windows path traversal via backslash in middleware.Static default filesystemEPSS 0.4%CVE-2025-37144MEDIUMAuthenticated Arbitrary File Download Vulnerabilities in a Low-Level Interface Library Affecting AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management InterfaceEPSS 0.4%CVE-2026-49244MEDIUMSFTPGo: Path confinement bypass in public browsable share partial ZIP downloadEPSS 0.4%CVE-2026-70460CRITICALrsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir SymlinkEPSS 0.4%CVE-2024-5824HIGHPath Traversal in parisneo/lollmsEPSS 0.4%CVE-2025-49303MEDIUMWordPress Frontend Admin by DynamiApps plugin <= 3.28.7 - Arbitrary File Download VulnerabilityEPSS 0.4%CVE-2025-27299MEDIUMWordPress MyTicket Events plugin <= 1.2.4 - Non-Arbitrary File Read vulnerabilityEPSS 0.4%CVE-2025-10468HIGHPath Traversal in Beyaz Computer's CityPLusEPSS 0.4%CVE-2026-54077HIGHArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated usersEPSS 0.4%CVE-2026-79676HIGHNLTK before 3.10.3 Path Traversal via Symlink BypassEPSS 0.4%CVE-2026-50567HIGHFission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directoryEPSS 0.4%CVE-2024-43373HIGHwebcrack has an Arbitrary File Write Vulnerability on Windows when Parsing and Saving a Malicious BundleEPSS 0.4%CVE-2026-58173MEDIUMVibe-Trading < 0.1.10 - Path Traversal via Persistent Memory TypeEPSS 0.4%CVE-2026-35492MEDIUMKedro-Datasets has a path traversal vulnerability in PartitionedDataset allows arbitrary file writeEPSS 0.4%CVE-2024-38717HIGHWordPress Booking Ultra Pro Appointments Booking Calendar plugin <= 1.1.13 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-3089MEDIUMActual Sync Server 26.2.1 - Authenticated Path TraversalEPSS 0.4%CVE-2025-13070MEDIUMCSV to SortTable <= 4.2 - Contributor+ LFIEPSS 0.4%