Weaknesses of type CWE-22

5,988 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-34726MEDIUMCopier `_subdirectory` allows template root escape via parent-directory traversalEPSS 0.4%CVE-2026-104417MEDIUMGhost 1.20.0 before 6.64.0 Path Traversal via Locale SettingEPSS 0.4%CVE-2020-1737HIGHA flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip moEPSS 0.4%CVE-2025-8406MEDIUMPath Traversal in zenml-io/zenmlEPSS 0.4%CVE-2026-67295MEDIUMFreeRDP before 3.29.0 Path Traversal via drive redirectionEPSS 0.4%CVE-2023-41057MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in hyper-bump-itEPSS 0.4%CVE-2025-14293MEDIUMWP Job Portal <= 2.4.0 - Authenticated (Subscriber+) Arbitrary File ReadEPSS 0.4%CVE-2025-68862HIGHWordPress Woo File Dropzone plugin <= 1.1.7 - Arbitrary File Deletion vulnerabilityEPSS 0.4%CVE-2026-77193HIGHeesy_ID2WP – Publish InDesign HTML5 <= 1.0.3 - Unauthenticated Path Traversal to Arbitrary File Read via 'id2wp_path' Query ParameterEPSS 0.4%CVE-2025-68921HIGHSteelSeries Nahimic 3 1.10.7 allows Directory traversal.EPSS 0.4%CVE-2025-27098MEDIUMUnwanted access to the entire file system vulnerability due to a missing check in `staticFiles` HTTP handler in graphql-meshEPSS 0.4%CVE-2026-22661HIGHprompts.chat Path Traversal via Skill File HandlingEPSS 0.4%CVE-2024-46327MEDIUMAn issue in the Http_handle object of VONETS VAP11G-300 v3.3.23.6.9 allows attackers to access sensitive files via a directory traversal.EPSS 0.4%CVE-2022-4773LOWcloudsync LocalFilesystemConnector.java getItem path traversalEPSS 0.4%CVE-2026-13224HIGHFireware OS Path Traversal in WebUI Management Agent Allows Arbitrary Local File ReadEPSS 0.4%CVE-2026-23942MEDIUMSFTP root escape via component-agnostic prefix check in ssh_sftpdEPSS 0.4%CVE-2025-61649LOWUserInfoCard: Check that performing user has permission to view log entries for number of past blocksEPSS 0.4%CVE-2026-86071LOWJunrar: LocalFolderExtractor mkdir escape allows directory creation outside extraction rootEPSS 0.4%CVE-2026-11769MEDIUMOperator - Namespaced User Path TraversalEPSS 0.4%CVE-2026-54014MEDIUMOpen WebUI: Sibling-Prefix Path Traversal via /cache/{path} in open-webui/open-webuiEPSS 0.4%