Weaknesses of type CWE-22

5,996 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-102123HIGHKiteworks Core Path TraversalEPSS 0.3%CVE-2024-12425LOWPath traversal leading to arbitrary .ttf file writeEPSS 0.3%CVE-2024-32163MEDIUMCMSeasy 7.7.7.9 is vulnerable to code execution.EPSS 0.3%CVE-2026-59944MEDIUMComposer: CVE-2026-59946 fix bypass via symlinked package bin pathEPSS 0.3%CVE-2025-8054HIGHPath Traversal vulnerability have been discovered in OpenText™ XM Fax.EPSS 0.3%CVE-2026-15801HIGHCri-o: cri-o: insufficient validation during container checkpoint restoreEPSS 0.3%CVE-2026-11423CRITICALPath Traversal in Altium Enterprise Server Collaboration Service Allows Privilege EscalationEPSS 0.3%CVE-2025-54292MEDIUMClient-Side Path Traversal in LXD-UIEPSS 0.3%CVE-2026-32709MEDIUMPX4 Autopilot MAVLink FTP Unauthenticated Path Traversal (Arbitrary File Read/Write/Delete)EPSS 0.3%CVE-2026-40923MEDIUMTekton Pipelines: VolumeMount path restriction bypass via missing filepath.Clean in /tekton/ checkEPSS 0.3%CVE-2024-6971LOWPath Traversal in parisneo/lollms-webuiEPSS 0.3%CVE-2026-7869MEDIUMLangflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcementEPSS 0.3%CVE-2025-67720MEDIUMPyrofork has a Path Traversal in download_media MethodEPSS 0.3%CVE-2022-36035HIGHFlux CLI Workload InjectionEPSS 0.3%CVE-2021-29088HIGHImproper limitation of a pathname to a restricted directory ('Path Traversal') in cgi component in Synology DiskStation Manager (DSM) beforeEPSS 0.3%CVE-2018-25194HIGHNominas 0.27 SQL Injection via username ParameterEPSS 0.3%CVE-2026-82035HIGHPyMuPDF 1.28.2 Path Traversal via extract_objects() Font BranchEPSS 0.3%CVE-2026-90959HIGHPulpcore: pulpcore: file:// scheme allowlist bypass in content upload file_url field enables arbitrary file read and pulp container registry signing key theftEPSS 0.3%CVE-2026-30240CRITICALBudibase PWA ZIP Upload Path Traversal Allows Reading Arbitrary Server Files Including All Environment SecretsEPSS 0.3%CVE-2026-51568HIGHmodelscope Agentscope v1.0.18-v1.0.0 is vulnerable to Path Traversal in write_text_file.EPSS 0.3%