Weaknesses of type CWE-22

6,017 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2025-15693LOWJCH Optimize 4.2.1 - 5.0.0 - Admin+ Path TraversalEPSS 0.3%CVE-2025-55214MEDIUMCopier safe template has filesystem write access outside destination pathEPSS 0.3%CVE-2026-19532MEDIUMPath Traversal in HAVELSAN's Liman MYSEPSS 0.3%CVE-2026-53951HIGHCopier: trust-prefix bypass via path traversal runs tasks unpromptedEPSS 0.3%CVE-2022-42280HIGHNVIDIA BMC contains a vulnerability in SPX REST auth handler, where an un-authorized attacker can exploit a path traversal, which may lead tEPSS 0.3%CVE-2026-84069MEDIUMWebFacing Email Accounts for cPanel 5.3 - 5.3.6 - Unauthenticated LFI via assets/index.phpEPSS 0.3%CVE-2024-27871MEDIUMA path handling issue was addressed with improved validation. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. An app mayEPSS 0.3%CVE-2026-51873HIGHDevika v1.0 is vulnerable to Directory Traversal in the Coder.save_code_to_project function, which allows attackers to write files outside tEPSS 0.3%CVE-2026-14967LOWPath traversal in github_workflows allows writing artifacts outside output directoryEPSS 0.3%CVE-2026-81716HIGHopenssl_encrypt before 1.4.9 Plugin Sandbox Path TraversalEPSS 0.3%CVE-2025-10406MEDIUMBlindMatrix e-Commerce < 3.1 - Contributor+ LFIEPSS 0.3%CVE-2024-41938MEDIUMA vulnerability has been identified in SINEC NMS (All versions < V3.0). The importCertificate function of the SINEC NMS Control web applicatEPSS 0.3%CVE-2026-22625MEDIUMImproper handling of filenames in certain HIKSEMI NAS products may lead to the exposure of sensitive system files.EPSS 0.3%CVE-2026-59732MEDIUMrclone archive extract allows S3 destination prefix escape via crafted archive pathsEPSS 0.3%CVE-2025-55201HIGHCopier safe template has arbitrary filesystem read/write accessEPSS 0.3%CVE-2021-36286HIGHDell SupportAssist Client Consumer versions 3.9.13.0 and any versions prior to 3.9.13.0 contain an arbitrary file deletion vulnerability thaEPSS 0.3%CVE-2025-62851MEDIUMLicense CenterEPSS 0.3%CVE-2026-101044HIGHpacquet before 12.0.0-alpha.5 Path Traversal via lockfile aliasEPSS 0.3%CVE-2026-19722MEDIUMWPvivid Backup & Migration < 0.9.133 - Admin+ Arbitrary File Write via Zip Slip in Backup RestoreEPSS 0.3%CVE-2026-40987HIGHRemote-file synchronizer in Spring Integration writes server-supplied filename under localDirectory without canonicalizationEPSS 0.3%