Weaknesses of type CWE-22

5,972 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-49238HIGHSFTP Server VM Escape in Canonical MultipassEPSS 0.4%CVE-2023-41291MEDIUMQuFirewallEPSS 0.4%CVE-2026-55156MEDIUMToken Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API EndpointsEPSS 0.4%CVE-2025-57712MEDIUMQsync CentralEPSS 0.4%CVE-2026-48129MEDIUMKestra task inputFiles accepts traversal filenames for worker file writesEPSS 0.4%CVE-2025-65838HIGHPublicCMS V5.202506.b is vulnerable to path traversal via the doUploadSitefile method.EPSS 0.4%CVE-2024-34808MEDIUMWordPress JCH Optimize plugin <= 4.2.0 - Path Traversal vulnerabilityEPSS 0.4%CVE-2026-28791HIGHPath Traversal in Media Upload Handle in TinaEPSS 0.4%CVE-2025-11182HIGHFile Download in GTONE ChangeFlowEPSS 0.4%CVE-2025-63372MEDIUMArticentgroup Zip Rar Extractor Tool 1.345.93.0 is vulnerable to Directory Traversal. The vulnerability resides in the ZIP file processing cEPSS 0.4%CVE-2026-60009HIGHIn Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled EPSS 0.4%CVE-2024-23774HIGHAn issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An unquoted Windows search path vulnerability exists in the KEPSS 0.4%CVE-2026-1703LOWLimited path traversal when installing wheel archivesEPSS 0.4%CVE-2026-40724MEDIUMWordPress Client Portal (Pro) plugin <= 5.6.2 - Arbitrary File Download vulnerabilityEPSS 0.4%CVE-2026-87030HIGHTanium addressed a path traversal vulnerability in Comply.EPSS 0.4%CVE-2026-65582HIGHWordPress AI Hub theme <= 1.3.10 - Arbitrary File Download vulnerabilityEPSS 0.4%CVE-2025-60242HIGHWordPress Download Counter plugin <= 1.4 - Arbitrary File Download vulnerabilityEPSS 0.4%CVE-2026-47277MEDIUMRuntipi: Unauthenticated arbitrary file read through app-store logo symlinksEPSS 0.4%CVE-2026-14194MEDIUMPath Traversal Allows Arbitrary File Download in Bilin Software's HUMANIST Digital Human ResourcesEPSS 0.4%CVE-2026-35605MEDIUMFile Browser has an access rule bypass via HasPrefix without trailing separator in path matchingEPSS 0.4%