Weaknesses of type CWE-22

6,002 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-96440HIGHFlowring Agentflow 4.0 - Improper Limitation of a Pathname to a Restricted Directory(Path Traversal)EPSS 0.3%CVE-2025-4748MEDIUMAbsolute path traversal in zip:unzip/1,2EPSS 0.3%CVE-2025-15491MEDIUMPost Slides <= 1.0.1 - Contributor+ Local File InclusionEPSS 0.3%CVE-2026-13426MEDIUMClient4 fails to validate path parametersEPSS 0.3%CVE-2024-53566MEDIUMAn issue in the action_listcategories() function of Sangoma Asterisk v22/22.0.0/22.0.0-rc1/22.0.0-rc2/22.0.0-pre1 allows attackers to executEPSS 0.3%CVE-2025-22238MEDIUMCVE-2025-22238 salt advisoryEPSS 0.3%CVE-2026-100533MEDIUMOpenClaw before 2026.8.1 Path Traversal via Unicode FallbackEPSS 0.3%CVE-2026-77757MEDIUMDirectorist 8.5 - 8.9.2 - Subscriber+ Arbitrary Image Move via REST v2 Listing SubmissionEPSS 0.3%CVE-2024-40712HIGHA path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege esEPSS 0.3%CVE-2026-103533LOWDavid-Crty databasement database-servers API Endpoint RestoreRequest.php 511 path traversalEPSS 0.3%CVE-2025-71427HIGHOffice-PowerPoint-MCP-Server through 2.0.7 Path Traversal via save_presentation and manage_imageEPSS 0.3%CVE-2026-42448LOWwormhole receive, with --output pointing at an existing directory can be path-traversedEPSS 0.3%CVE-2025-63680HIGHNero BackItUp in the Nero Productline is vulnerable to a path parsing/UI rendering flaw (CWE-22) that, in combination with Windows ShellExecEPSS 0.3%CVE-2026-0655MEDIUMPath Traversal on TP-Link Deco BE25EPSS 0.3%CVE-2026-93986LOWrclone before 1.75.1 Path Traversal via Directory Listing NamesEPSS 0.3%CVE-2025-50819HIGHDirectory traversal vulnerability in beiyuouo arxiv-daily thru 2025-05-06 (commit fad168770b0e68aef3e5acfa16bb2e7a7765d687) when parsing theEPSS 0.3%CVE-2026-11847MEDIUMIntegration Corp|iVEC-IEI Virtualization Edge Computer - Arbitrary File DeletionEPSS 0.3%CVE-2026-10278MEDIUMishayoyo excel-mcp read_file/write_file index.ts path traversalEPSS 0.3%CVE-2026-34657MEDIUMCAI Content Credentials | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)EPSS 0.3%CVE-2025-48395MEDIUMAn attacker with authenticated and privileged access could modify the contents of a non-sensitive file by traversing the path in the limitedEPSS 0.3%