Weaknesses of type CWE-22

5,991 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-86087MEDIUMIBM® Db2® could allow an authenticated user to send a specially crafted request to write arbitrary files on the systemEPSS 0.3%CVE-2025-30470MEDIUMA path handling issue was addressed with improved logic. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 1EPSS 0.3%CVE-2026-18465MEDIUMWP Maps Pro < 6.1.3 - Unauthenticated Local File InclusionEPSS 0.3%CVE-2026-71426HIGHGetSimple CMS: Authenticated Stored Local File Inclusion (LFI) via page "template" fieldEPSS 0.3%CVE-2025-53080HIGHImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Samsung DMS(Data Management Server) allows authenticated aEPSS 0.3%CVE-2026-23484MEDIUMBlinko: Authenticated Arbitrary File Write - saveDevPluginEPSS 0.3%CVE-2026-14470MEDIUMLangflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base componentsEPSS 0.3%CVE-2026-34371MEDIUMLibreChat Affected by Arbitrary File Write via `execute_code` Artifact Filename TraversalEPSS 0.3%CVE-2026-12089MEDIUMWS Optimize – All-in-One Speed Booster & Cache Tools <= 3.3.19 - Authenticated (Editor+) Arbitrary File ReadEPSS 0.3%CVE-2026-64777MEDIUMA malicious builder peer may be able to request an in-context file by name from the host and receive the contents of whatever the name resolEPSS 0.3%CVE-2026-48482CRITICALGLPI: RCE via Form importEPSS 0.3%CVE-2024-36795MEDIUMInsecure permissions in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to access URLs and directories embedded within the fiEPSS 0.3%CVE-2026-86334MEDIUMCLI Path Traversal via Content-Disposition in LXD Image Export/CopyEPSS 0.3%CVE-2026-65829MEDIUMMPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readersEPSS 0.3%CVE-2026-103754MEDIUMAnsible-runner: ansible-runner: path traversal and symlink escape in unstream_dir() allows file write outside the target directoryEPSS 0.3%CVE-2026-96884MEDIUMMantisZip Preview MainWindow.UI.cs Path.Combine path traversalEPSS 0.3%CVE-2018-25421HIGHOpen STA Manager 2.3 Arbitrary File Download via Path TraversalEPSS 0.3%CVE-2025-54959MEDIUMPowered BLUE Server versions 0.20130927 and prior contain a path traversal vulnerability. If this vulnerability is exploited, an arbitrary fEPSS 0.3%CVE-2021-35230MEDIUMUnquoted Path Vulnerability (SMB Login) in Kiwi CatToolsEPSS 0.3%CVE-2024-2045MEDIUMSession 1.17.5 - LFR via chat attachmentEPSS 0.3%