Weaknesses of type CWE-22

5,991 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-104478HIGHFormwork before 2.3.13 Path Traversal via BackupController Download and DeleteEPSS 0.4%CVE-2026-35592MEDIUMpyLoad has an Incomplete Tar Path Traversal Fix in UnTar._safe_extractall via os.path.commonprefix BypassEPSS 0.4%CVE-2026-44788MEDIUMSharpCompress: Directory traversal via directory entries in WriteToDirectory (zip slip variant)EPSS 0.4%CVE-2025-69904MEDIUMLinkstack v4.8.4 and earlier is vulnerable to Path Traversal, which allows an administrator to read arbitrary files on the server by manipulEPSS 0.4%CVE-2026-61431MEDIUMPraisonAI before 4.6.78 Path Traversal via ContextGathererEPSS 0.4%CVE-2026-103293MEDIUMMPG < 4.2.3 - Editor+ Arbitrary File Read via Project ImportEPSS 0.4%CVE-2025-64235MEDIUMWordPress Tuturn plugin < 3.6 - Arbitrary File Download vulnerabilityEPSS 0.4%CVE-2026-28800MEDIUMNatro Macro: Malicious actions allowed through Discord RC Commands by any userEPSS 0.4%CVE-2025-29213MEDIUMA zip slip vulnerability in the component \service\migrate\MigrateForm.java of JEEWMS v3.7 allows attackers to execute arbitrary code via a EPSS 0.4%CVE-2026-30848MEDIUMParse Server: `PagesRouter` path traversal allows reading files outside configured pages directoryEPSS 0.4%CVE-2025-2830MEDIUMInformation Disclosure of /tmp directory listingEPSS 0.4%CVE-2026-32262MEDIUMCraft CMS has a Path Traversal Vulnerability in AssetsControllerEPSS 0.4%CVE-2026-66382MEDIUMAuthenticated users may write files outside the intended Artifactory work directoryEPSS 0.4%CVE-2026-16033HIGHArbitrary file read+write on host via templates/ symlink in malicious imageEPSS 0.4%CVE-2025-58769LOWauth0-PHP: Improper File Type Handling in Bulk User ImportEPSS 0.4%CVE-2026-59280MEDIUMSpring Framework Path Traversal via Backslash in SpringTemplateLoaderEPSS 0.3%CVE-2025-8522LOWgivanz Vvvebjs node.js save.php path traversalEPSS 0.3%CVE-2026-55747MEDIUMPocketFlow - Path Traversal in pocketflow-coding-agent Cookbook Example File ToolsEPSS 0.3%CVE-2026-77260HIGHMCP Atlassian: Arbitrary local file READ via unconstrained file_path in upload_attachment (Confluence + Jira)EPSS 0.3%CVE-2026-33171MEDIUMStatamic has a path traversal in file dictionary fieldtypeEPSS 0.3%