Weaknesses of type CWE-22

5,979 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-53584MEDIUMlibgit2: Submodule path traversalEPSS 0.4%CVE-2026-49453HIGHJoplin: Path traversal in resource sync — silent arbitrary file write outside the resource directoryEPSS 0.4%CVE-2026-3029HIGHCVE-2026-3029EPSS 0.4%CVE-2026-45482HIGHMicrosoft Visual Studio Code CoPilot Chat Security Feature Bypass VulnerabilityEPSS 0.4%CVE-2020-3588HIGHCisco Webex Meetings Desktop App Arbitrary Code Execution VulnerabilityEPSS 0.4%CVE-2026-19991HIGHUsersWP <= 1.2.70 - Authenticated (Subscriber+) Arbitrary File DeletionEPSS 0.4%CVE-2023-20229HIGHA vulnerability in the CryptoService function of Cisco Duo Device Health Application for Windows could allow an authenticated, local attackeEPSS 0.4%CVE-2026-57321HIGHWordPress H5P plugin <= 1.17.7 - Arbitrary File Deletion vulnerabilityEPSS 0.4%CVE-2026-34750MEDIUMPayload has Insufficient Filename Validation in Client-Upload Signed-URL EndpointsEPSS 0.4%CVE-2026-21726MEDIUMLoki Path Traversal - CVE-2021-36156 BypassEPSS 0.4%CVE-2026-57696HIGHWordPress Picture Gallery plugin <= 1.6.5 - Arbitrary File Deletion vulnerabilityEPSS 0.4%CVE-2026-9154HIGHArbitrary File Write in Rapid7 InsightConnect Sed PluginEPSS 0.4%CVE-2026-41863MEDIUMLLM-influenced filename used unsanitized in Path.resolve before file write in Spring AI support for Anthropic Skills APIEPSS 0.4%CVE-2026-57346HIGHWordPress Embed Privacy plugin <= 1.12.3 - Arbitrary File Deletion vulnerabilityEPSS 0.4%CVE-2026-9138MEDIUMLangflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing componentsEPSS 0.4%CVE-2026-4502MEDIUMArbitrary File Write and Remote Code Execution Vulnerability in Langflow v2 APIEPSS 0.4%CVE-2026-79705MEDIUMPodman: buildah: buildah/copier: directory escape via crafted tar symlinks when used outside buildah by non-root callersEPSS 0.4%CVE-2024-1163HIGHPath traversal vulnerability in mapshaperEPSS 0.4%CVE-2026-87727MEDIUMa-blog cms Ver. 3.2.33 and earlier contains a path traversal vulnerability, which allows an unauthenticated attacker to read or delete arbitEPSS 0.4%CVE-2026-77259HIGHMCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentialsEPSS 0.4%