Weaknesses of type CWE-22

5,987 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2024-25156MEDIUMPath traversal in GoAnywhere MFT 7.4.1 and EarlierEPSS 0.4%CVE-2026-96824MEDIUMWordPress Template Kit – Import plugin <= 1.0.16 - Arbitrary File Deletion vulnerabilityEPSS 0.4%CVE-2026-33220MEDIUMWeblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repositoryEPSS 0.4%CVE-2025-54748MEDIUMWordPress MapSVG Plugin < 8.6.12 - Arbitrary File Download VulnerabilityEPSS 0.4%CVE-2024-7263CRITICALArbitrary Code Execution in WPS OfficeEPSS 0.4%CVE-2024-30143MEDIUMA path traversal vulnerability in HCL AppScan Traffic RecorderEPSS 0.4%CVE-2026-45711MEDIUMMailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDsEPSS 0.4%CVE-2022-28541MEDIUMUncontrolled search path element vulnerability in Samsung Update prior to version 3.0.77.0 allows attackers to execute arbitrary code as SamEPSS 0.4%CVE-2025-61653LOWExtension:TextExtracts does not check for authorizeRead when returning extractsEPSS 0.4%CVE-2026-102810HIGHMarmite through 0.4.2 Path Traversal via Development ServerEPSS 0.4%CVE-2026-73079HIGHSub2API: Path traversal in the Responses subpath routes lets an authenticated tenant relay requests to arbitrary upstream endpoints using pooled account credentialsEPSS 0.4%CVE-2026-51907HIGHIn TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vulnerability allows attackers to write imaEPSS 0.4%CVE-2026-35487MEDIUMtext-generation-webui has a Path Traversal in load_prompt() — .txt file read without authenticationEPSS 0.4%CVE-2026-49339HIGHPath traversal in getPlaylist/deletePlaylist bypasses ownership check: any authenticated user can read or delete any other user's playlistEPSS 0.4%CVE-2026-41843MEDIUMSpring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFluxEPSS 0.4%CVE-2026-40090HIGHZarf has a Path Traversal via Malicious Package Metadata.Name — Arbitrary File WriteEPSS 0.4%CVE-2025-0614MEDIUMInput validation vulnerability in Qualifio's Wheel of FortuneEPSS 0.4%CVE-2026-73291HIGHSeerr: Path traversal to RCE via /avatarproxy image cache filename from upstream ETagEPSS 0.4%CVE-2026-84842HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.4%CVE-2026-41691MEDIUMi18next-http-backend has Path Traversal & URL Injection via Unsanitised lng/nsEPSS 0.4%