Weaknesses of type CWE-22

6,017 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2025-69620MEDIUMA path traversal in Moo Chan Song v4.5.7 allows attackers to cause a Denial of Service (DoS) via writing files to the internal storage.EPSS 0.3%CVE-2023-42947HIGHA path handling issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 aEPSS 0.3%CVE-2026-12568MEDIUMArbitrary File Write in postman_download moduleEPSS 0.3%CVE-2026-59839MEDIUMA improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortEPSS 0.3%CVE-2023-24592HIGHPath traversal in the some Intel(R) oneAPI Toolkits and Component software before version 2023.1 may allow authenticated user to potentiallyEPSS 0.3%CVE-2025-43314MEDIUMA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7, mEPSS 0.3%CVE-2026-54561MEDIUMMCP Memory Keeper: Arbitrary local file read in mcp-memory-keeper context_import via unvalidated filePathEPSS 0.2%CVE-2026-15791LOWLLB file operation can be tricked to remove /tmp directory contentsEPSS 0.2%CVE-2025-43196HIGHA path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura EPSS 0.2%CVE-2024-27827MEDIUMThis issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14.5, macOS Ventura 13.6.7. An app may be abEPSS 0.2%CVE-2024-44190MEDIUMA path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7EPSS 0.2%CVE-2022-3560MEDIUMA flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service unit runs a script tEPSS 0.2%CVE-2025-43191MEDIUMA path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura EPSS 0.2%CVE-2026-3479NONEpkgutil.get_data() does not enforce documented restrictionsEPSS 0.2%CVE-2026-8770MEDIUMcontinuedev continue JSON-RPC Server lsTool.ts lsTool path traversalEPSS 0.2%CVE-2025-3424HIGH3.2.1 Arbitrary File Read in insecure .NET Remoting TCP ChannelEPSS 0.2%CVE-2022-4123LOWA flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resultingEPSS 0.2%CVE-2024-0129MEDIUMNVIDIA NeMo contains a vulnerability in SaveRestoreConnector where a user may cause a path traversal issue via an unsafe .tar file extractioEPSS 0.2%CVE-2026-54319MEDIUMDaytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escapeEPSS 0.2%CVE-2022-29093HIGHDell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versionEPSS 0.2%