Weaknesses of type CWE-22

5,997 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-77825MEDIUMIBM ContextForge MCP Gateway is affected by path traversalEPSS 0.3%CVE-2025-61641LOWAPI list=allpages with maxsize is making really slow queriesEPSS 0.3%CVE-2026-90959HIGHPulpcore: pulpcore: file:// scheme allowlist bypass in content upload file_url field enables arbitrary file read and pulp container registry signing key theftEPSS 0.3%CVE-2026-82035HIGHPyMuPDF 1.28.2 Path Traversal via extract_objects() Font BranchEPSS 0.3%CVE-2026-2500MEDIUMQuick Playground <= 1.3.4 - Authenticated (Administrator+) Arbitrary File Read via 'filename' ParameterEPSS 0.3%CVE-2025-49089MEDIUMwangxutech MoneyPrinterTurbo 1.2.6 allows path traversal via /api/v1/download/ URIs such as /api/v1/download//etc/passwd.EPSS 0.3%CVE-2024-9597HIGHPath Traversal in parisneo/lollmsEPSS 0.3%CVE-2026-15789MEDIUMMalicious client can bypass destination directory validation on local sources uploadEPSS 0.3%CVE-2021-1436MEDIUMCisco IOS XE SD-WAN Software Path Traversal VulnerabilityEPSS 0.3%CVE-2026-97164HIGHJoomla Extension - svenbluege.de - Path Traversal in Clear Cache task in Event Gallery extension < 6.5.0EPSS 0.3%CVE-2023-41973HIGHLack of input santization on Zscaler Client Connector enables arbitrary code executionEPSS 0.3%CVE-2026-6903HIGHPath Traversal Vulnerability in LabOne User InterfaceEPSS 0.3%CVE-2022-40264MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ICONICS/Mitsubishi Electric GENESIS64 versioEPSS 0.3%CVE-2022-39210LOWAccess to internal files of the Nextcloud Android appEPSS 0.3%CVE-2020-25243MEDIUMA vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.4). A zip slip vulnerability could be triggered while importingEPSS 0.3%CVE-2025-6210MEDIUMHardlink-Based Path Traversal in run-llama/llama_indexEPSS 0.3%CVE-2026-14505MEDIUMTanium addressed a path traversal vulnerability in Tanium Data Service.EPSS 0.3%CVE-2026-105125MEDIUMLaraDashboard before 1.4.8 Path Traversal via /api/translations/{lang} EndpointEPSS 0.3%CVE-2024-44255HIGHA path handling issue was addressed with improved logic. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 1EPSS 0.3%CVE-2026-2216MEDIUMrachelos WeRSS we-mp-rss tools.py download_export_file path traversalEPSS 0.3%