Weaknesses of type CWE-22

5,979 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-44298MEDIUMKimai: Arbitrary file read in invoice PDF renderer (admin)EPSS 0.4%CVE-2024-57186MEDIUMIn Erxes <1.6.2, an unauthenticated attacker can read arbitrary files from the system using a Path Traversal vulnerability in the /read-fileEPSS 0.4%CVE-2025-59002HIGHWordPress BM Content Builder Plugin < 3.16.3.3 - Arbitrary File Deletion VulnerabilityEPSS 0.4%CVE-2026-7704MEDIUMAV Stumpfl Pixera Two Media Server Service Port 1338 path traversalEPSS 0.4%CVE-2026-25062MEDIUMOutline Affected an Arbitrary File Read via Path Traversal in JSON ImportEPSS 0.4%CVE-2026-4917MEDIUMIBM Guardium Data Protection is affected by multiple vulnerabilitiesEPSS 0.4%CVE-2026-97163CRITICALJoomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29EPSS 0.4%CVE-2025-6731MEDIUMyzcheng90 X-SpringBoot APK File apk uploadApk path traversalEPSS 0.4%CVE-2026-97161CRITICALJoomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29EPSS 0.4%CVE-2024-53844MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in labsai/eddiEPSS 0.4%CVE-2026-22573MEDIUMAn improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6EPSS 0.4%CVE-2026-6262MEDIUMBetheme <= 28.4 - Authenticated (Contributor+) Arbitrary File Deletion via 'mfn-icon-upload'EPSS 0.4%CVE-2026-54732MEDIUMlibreoffice-convert: path traversal / arbitrary file writeEPSS 0.4%CVE-2026-49991HIGHRustFS Snowball Auto-Extract: Path Traversal allows cross-bucket object injectionEPSS 0.4%CVE-2026-27800HIGHZed has Zip Slip Path Traversal in Extension Archive ExtractionEPSS 0.4%CVE-2026-2552MEDIUMZenTao Editor control.php delete path traversalEPSS 0.4%CVE-2026-53554HIGHSQLBot: Arbitrary File Write via parseExcel Leading to Code Execution Through Alembic Import ProcessingEPSS 0.4%CVE-2025-54021HIGHWordPress Simple File List plugin <= 6.1.14 - Arbitrary File Download vulnerabilityEPSS 0.4%CVE-2026-30973MEDIUMZip Slip arbitrary file write in @appium/support ZIP extractionEPSS 0.4%CVE-2026-94620CRITICALClassroom 50 vulnerable to arbitrary file overwrite on the teacher's machine via symlink in a student repo (gh teacher download)EPSS 0.4%