Weaknesses of type CWE-22

5,988 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2024-58386HIGHZoneMinder 1.37.x Path Traversal via files viewEPSS 0.4%CVE-2026-49246LOWJellyfin: Potential MKV attachment filename path traversal to RCEEPSS 0.4%CVE-2026-49833MEDIUMDSpace: Path Traversal possible in LDN message generationEPSS 0.4%CVE-2025-22601LOWClient Side Path Traversal using activate account route in DiscourseEPSS 0.4%CVE-2026-32193HIGHAzure Kubernetes Service (AKS) Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-48070HIGHDocmost: Avatar URL path traversal in avatar cleanup leads to arbitrary local file deletionEPSS 0.4%CVE-2025-59414LOWNuxt Client-Side Path Traversal in Nuxt Island Payload RevivalEPSS 0.4%CVE-2026-102242HIGHPath Traversal via Symlink Following in allowedLocalRoots in MCP Toolbox for DatabasesEPSS 0.4%CVE-2025-69226MEDIUMAIOHTTP allows for a brute-force leak of internal static filepath componentsEPSS 0.4%CVE-2024-3318MEDIUMSailPoint Identity Security Cloud Connector File Path Traversal VulnerabilityEPSS 0.4%CVE-2024-21904MEDIUMQTS, QuTS heroEPSS 0.4%CVE-2026-101126MEDIUMJoomla Extension - balbooa.com - File meta data tampering in Balbooa Forms < 2.4.3.4EPSS 0.4%CVE-2026-102424HIGHJoomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4EPSS 0.4%CVE-2025-29843MEDIUMA vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files.EPSS 0.4%CVE-2026-50558MEDIUMPenelope unsafe tar extraction allows arbitrary local file write via crafted session archiveEPSS 0.4%CVE-2023-39957HIGHPath traversal allows tricking the Talk Android app into writing files into it's root directoryEPSS 0.4%CVE-2026-18849MEDIUMIBM OpenBMC Code ExecutionEPSS 0.4%CVE-2025-71394LOWSurrealDB before 2.2.2 Local File Read via DEFINE ANALYZEREPSS 0.4%CVE-2026-39489MEDIUMWordPress Download Monitor plugin <= 5.1.9 - Non-Arbitrary File Download vulnerabilityEPSS 0.4%CVE-2026-104417MEDIUMGhost 1.20.0 before 6.64.0 Path Traversal via Locale SettingEPSS 0.4%