Weaknesses of type CWE-22

6,020 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2022-29093HIGHDell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versionEPSS 0.2%CVE-2022-29094HIGHDell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versionEPSS 0.2%CVE-2026-101885HIGHZeroClaw before 0.8.5 Path Traversal via Plugin Manifest wasm_pathEPSS 0.2%CVE-2026-78394MEDIUMLink Library < 7.9.6 - Contributor+ Path Traversal via 'filepath' ParameterEPSS 0.2%CVE-2024-31965MEDIUMA vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 ConferenEPSS 0.2%CVE-2026-55557HIGHbrowse-mcp: Arbitrary file write via unconfined download and state pathsEPSS 0.2%CVE-2024-31552HIGHCuteHttpFileServer v.3.1 version has an arbitrary file download vulnerability, which allows attackers to download arbitrary files on the serEPSS 0.2%CVE-2024-36508MEDIUMAn improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.EPSS 0.2%CVE-2023-40439LOWA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.6 and iPadOS 16.6, macOS VEPSS 0.2%CVE-2026-18114MEDIUMIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS 0.2%CVE-2023-25508MEDIUMNVIDIA DGX-1 BMC contains a vulnerability in the IPMI handler, where an attacker with the appropriate level of authorization can upload and EPSS 0.2%CVE-2025-0750MEDIUMCri-o: cri-o path traversal in log handling functions allows arbitrary unmountingEPSS 0.2%CVE-2023-6407MEDIUM A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary fiEPSS 0.2%CVE-2026-73234HIGHFreeCAD: FCStd path traversal allows arbitrary file write via unsanitized file attribute in PropertyFileIncluded::Restore()EPSS 0.2%CVE-2026-41972MEDIUMPath traversal vulnerability in the SMS app. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.2%CVE-2025-43250MEDIUMA path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura EPSS 0.2%CVE-2026-24686MEDIUMgo-tuf Path Traversal in TAP 4 Multirepo Client Allows Arbitrary File Write via Malicious Repository NamesEPSS 0.2%CVE-2026-51888HIGHlangflow-ai langflow v1.8.4 is affected by: Directory Traversal. The impact is: Arbitrary file write outside the intended workspace or storaEPSS 0.2%CVE-2026-47487MEDIUMNVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repository to be read, wrEPSS 0.2%CVE-2024-0849MEDIUMLeanote 2.7.0 - Local File ReadEPSS 0.2%