Weaknesses of type CWE-22

5,975 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2025-29844MEDIUMA vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information.EPSS 0.4%CVE-2026-41656MEDIUMAdmidio: Path Traversal via Unvalidated `name` Parameter in Document Add Mode Enables Arbitrary Server File ReadEPSS 0.4%CVE-2026-35454HIGHCode Extension Marketplace has a Zip Slip Path TraversalEPSS 0.4%CVE-2025-29845MEDIUMA vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files.EPSS 0.4%CVE-2025-68907HIGHWordPress Hostme v2 theme <= 7.0 - Arbitrary File Deletion vulnerabilityEPSS 0.4%CVE-2026-55677HIGHEcho: Encoded slash (%2F) bypasses route-level protection and exposes static filesEPSS 0.4%CVE-2026-47735HIGHArc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checksEPSS 0.4%CVE-2026-104983MEDIUMLinux Mint Xreader PDF Attachment Saving ev-window.c g_file_get_child path traversalEPSS 0.4%CVE-2026-42496CRITICALArchive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directoryEPSS 0.4%CVE-2022-44749MEDIUMOpening workflows from untrusted resources may override arbitrary file system contentsEPSS 0.4%CVE-2025-52450MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux EPSS 0.4%CVE-2022-36007MEDIUMPartial Path Traversal in com.github.jlangch:veniceEPSS 0.4%CVE-2025-22397MEDIUMDell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions 6.10.80.00 through 7.20.10.50 and DEPSS 0.4%CVE-2024-32729HIGHWordPress ChatBot Conversational Forms plugin <= 1.1.8 - Arbitrary File Download vulnerabilityEPSS 0.4%CVE-2026-40163HIGHSaltcorn has an Unauthenticated Path Traversal in sync endpoints allows arbitrary file write and directory readEPSS 0.4%CVE-2026-55393CRITICALLocal File Inclusion in Teledyne FLIR Robots running Aware2EPSS 0.4%CVE-2025-59566HIGHWordPress Workreap (theme's plugin) plugin <= 3.3.5 - Arbitrary File Deletion vulnerabilityEPSS 0.4%CVE-2025-58959HIGHWordPress Taskbot plugin <= 6.4 - Arbitrary File Deletion vulnerabilityEPSS 0.4%CVE-2025-42906MEDIUMDirectory Traversal vulnerability in SAP Commerce CloudEPSS 0.4%CVE-2026-82521MEDIUMparsedmarc 9.0.6 < 11.0.1 Path Traversal via Forensic Report SubjectEPSS 0.4%