Weaknesses of type CWE-22

5,988 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-85185CRITICALPath traversal in LXD btrfs storage driver allows arbitrary file deletion and write on host as rootEPSS 0.4%CVE-2026-96275HIGHFlatpak: flatpak: arbitrary write access as root via extra-data extractionEPSS 0.4%CVE-2023-0592MEDIUMPath traversal in jeffersonEPSS 0.4%CVE-2026-97242MEDIUMWordPress WEBO MCP plugin <= 3.0.18 - Arbitrary File Deletion vulnerabilityEPSS 0.4%CVE-2023-2110HIGHObsidian Local File DisclosureEPSS 0.4%CVE-2025-62855LOWFile Station 5EPSS 0.4%CVE-2026-59294MEDIUMArbitrary File Write via Path Traversal in ResourceCacheServiceEPSS 0.4%CVE-2025-64346MEDIUMarchives: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')EPSS 0.4%CVE-2026-39359HIGHWazuh: Unauthenticated Path Traversal in authd via Agent Group NameEPSS 0.4%CVE-2025-64485MEDIUMCVAT: Mounted share file overwrite via crafted requestEPSS 0.4%CVE-2026-78591MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Kibana Leading to Unauthorized Resource DeletionEPSS 0.4%CVE-2026-43901MEDIUMWireshark MCP: Arbitrary file write via export_objects when WIRESHARK_MCP_ALLOWED_DIRS is not configuredEPSS 0.4%CVE-2026-88843HIGHMasterStudy LMS 3.5.29 - < 3.7.50 - Contributor+ LFI via Elementor Courses Categories WidgetEPSS 0.4%CVE-2026-32310MEDIUMCryptomator: Unverified masterkeyfile key IDs can access arbitrary local or UNC pathsEPSS 0.4%CVE-2026-16531MEDIUMPcp: pcp: arbitrary file creation via path traversal in pmproxy logger servletEPSS 0.4%CVE-2025-15020MEDIUMGotham Block Extra Light <= 1.5.0 - Authenticated (Contributor+) Arbitrary File Read via 'ghostban' ShortcodeEPSS 0.4%CVE-2026-86105MEDIUMFireware OS Improper Authorization in Access Portal Reverse ProxyEPSS 0.4%CVE-2026-18672HIGHRadImageEditor ClientState Unauthenticated Arbitrary File Read Vulnerability in Telerik UI for ASP.NET AJAXEPSS 0.4%CVE-2025-55011MEDIUMKanboard Path Traversal in File Write via Task File Upload ApiEPSS 0.4%CVE-2026-21851MEDIUMMONAI has Path Traversal (Zip Slip) in NGC Private Bundle DownloadEPSS 0.4%