Weaknesses of type CWE-22

6,020 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-92131MEDIUMJenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to the library PipelineEPSS 0.2%CVE-2022-40976MEDIUMPILZ: Multiple products affected by ZipSlipEPSS 0.2%CVE-2026-29064HIGHZarf: Symlink targets in archives are not validated against destination directoryEPSS 0.2%CVE-2024-5821MEDIUMLocal File Inclusion (LFI) in stitionai/devikaEPSS 0.2%CVE-2026-7318MEDIUMelie mcp-project research_server.py search_papers path traversalEPSS 0.2%CVE-2026-30290HIGHAn arbitrary file overwrite vulnerability in InTouch Contacts & Caller ID APP v6.38.1 allows attackers to overwrite critical internal files EPSS 0.2%CVE-2021-27798—privileged directory transversal.in Brocade Fabric OS versions 7.4.1.x and 7.3.xEPSS 0.2%CVE-2022-41667HIGHA CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that allows adversaries with lEPSS 0.2%CVE-2026-27115HIGHADB Explorer is Vulnerable to Arbitrary Directory Deletion via Command-Line ArgumentEPSS 0.2%CVE-2026-32146HIGHImproper Path Validation in Git Dependency Handling Allows Arbitrary File System ModificationEPSS 0.2%CVE-2025-3718MEDIUMClient-side path traversal in Guardian/CMC before 25.2.0EPSS 0.2%CVE-2025-3223MEDIUMWorkstationST EGD Configuration Server Path Traversal VulnerabilityEPSS 0.2%CVE-2026-6855HIGHInstructlab: instructlab: path traversal allows arbitrary directory creation and file writeEPSS 0.2%CVE-2026-48105HIGHArc Enterprise cluster FSM applyRegisterFile accepts arbitrary file paths without validation, enabling cluster-wide path-traversal worm primitiveEPSS 0.2%CVE-2024-13894MEDIUMPath traversal in Smartwares camerasEPSS 0.2%CVE-2026-43940HIGHelecterm: Path traversal in electerm runWidget leads to arbitrary code executionEPSS 0.2%CVE-2026-52755HIGHGhidra < 12.0.4 - Path Traversal via Zip Slip in Theme ImportEPSS 0.2%CVE-2026-52752HIGHGhidra < 12.0.2 - Path Traversal in Extension Installer via ZIP Entry NamesEPSS 0.2%CVE-2025-9963CRITICALPath TraversalEPSS 0.2%CVE-2026-57171HIGHTrestle is vulnerable to arbitrary file write via path traversal in author generate commands (Incomplete fix of CVE-2026-46345)EPSS 0.2%