Weaknesses of type CWE-22

5,988 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-55828MEDIUMqbee transport: Symlink-chain path traversal in tar extraction (one level outside destination)EPSS 0.4%CVE-2026-23481MEDIUMBlinko: Authenticated Arbitrary File Write - saveAdditionalDevFileEPSS 0.4%CVE-2025-61784HIGHLLaMA Factory's Chat API has Critical SSRF and LFI VulnerabilitiesEPSS 0.4%CVE-2026-39245MEDIUMdecompress before 4.2.2 contains an improper path containment check that enables directory traversal and arbitrary file write. The safeMakeDEPSS 0.4%CVE-2026-40256MEDIUMWeblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix CollisionEPSS 0.4%CVE-2026-77270MEDIUMMCP Atlassian: Arbitrary File Read via Upload Attachment ToolsEPSS 0.4%CVE-2026-78485HIGHDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper LimitatiEPSS 0.4%CVE-2026-77253HIGHMCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local filesEPSS 0.4%CVE-2026-33462MEDIUMPath Traversal in Kibana Leading to Unauthorized Deletion of User AccountsEPSS 0.4%CVE-2026-96276MEDIUMFlatpak: flatpak: arbitrary write in host context via flatpak build-initEPSS 0.4%CVE-2026-10213MEDIUMAstrBotDevs AstrBot API Endpoint delete path traversalEPSS 0.4%CVE-2026-12211MEDIUMIntelbras iNVU 7016 FT Web syslog path traversalEPSS 0.4%CVE-2025-13681MEDIUMBFG Tools – Extension Zipper <= 1.0.7 - Authenticated (Administrator+) Path Traversal via 'first_file' ParameterEPSS 0.4%CVE-2026-29509MEDIUMPatool < 4.0.5 Path Traversal via safe_extract() FunctionEPSS 0.4%CVE-2026-27522HIGHOpenClaw < 2026.2.24 - Arbitrary File Read via sendAttachment and setGroupIcon Message ActionsEPSS 0.4%CVE-2024-54489MEDIUMA path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura EPSS 0.4%CVE-2026-47699MEDIUMConfidential Containers Guest Components image-rs: zip-slip-class arbitrary file write via absolute entry path in hardlink fallbackEPSS 0.4%CVE-2026-69445HIGHWindows Compressed Folder Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-48820MEDIUMCakePHP: View::element() is missing a path containment checkEPSS 0.4%CVE-2026-49246LOWJellyfin: Potential MKV attachment filename path traversal to RCEEPSS 0.4%