Weaknesses of type CWE-22

5,974 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-103044CRITICALEasyTimeline should not serve image maps as application/xmlEPSS 0.4%CVE-2023-42961MEDIUMA path handling issue was addressed with improved validation. This issue is fixed in iOS 17 and iPadOS 17, iOS 16.7 and iPadOS 16.7, macOS SEPSS 0.4%CVE-2026-34523MEDIUMSillyTavern: Path traversal allows file existence oracleEPSS 0.4%CVE-2026-104982MEDIUMLinux Mint Xreader EPUB File epub-document.c g_strdup_printf path traversalEPSS 0.4%CVE-2026-76357HIGHRemote Code Execution (RCE) through Path Traversal in the REST API in Splunk SOAREPSS 0.4%CVE-2024-8647MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLabEPSS 0.4%CVE-2026-71283MEDIUMFledge IoT Gateway Backup Restore Tar Path TraversalEPSS 0.4%CVE-2025-11842MEDIUMShazwazza Smidge Bundle path traversalEPSS 0.4%CVE-2025-14727HIGHNGINX Ingress Controller vulnerabilityEPSS 0.4%CVE-2026-70428MEDIUMJenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file parameter names, allowEPSS 0.4%CVE-2026-8754MEDIUMAstrBotDevs AstrBot File Upload chat.py post_file path traversalEPSS 0.4%CVE-2026-18640HIGHVelociraptor directory traversal via the NewNotebook APIEPSS 0.4%CVE-2026-54286MEDIUMHono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)EPSS 0.4%CVE-2025-60915HIGHAn issue in the size query parameter (/views/file.py) of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execEPSS 0.4%CVE-2025-27147HIGHGLPI Inventory plugin has Improper Access Control VulnerabilityEPSS 0.4%CVE-2019-10934—A vulnerability has been identified in TIA Portal V14 (All versions), TIA Portal V15 (All versions < V15.1 Update 7), TIA Portal V16 (All veEPSS 0.4%CVE-2026-25228MEDIUMSignalK Server has Path Traversal leading to information disclosureEPSS 0.4%CVE-2026-74907HIGHGrav before 2.0.15 Path Traversal via plugin-asset-map.phpEPSS 0.4%CVE-2026-27117MEDIUMbit7z has a path traversal vulnerabilityEPSS 0.4%CVE-2024-47166LOWOne-level read path traversal in `/custom_component` in GradioEPSS 0.4%