Weaknesses of type CWE-22

6,020 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2023-41780MEDIUMUnsafe DLL Loading Vulnerability in ZTE ZXCLOUD iRAIEPSS 0.2%CVE-2026-94185MEDIUMnvm alias resolution follows `..` and discloses files outside $NVM_DIR/aliasEPSS 0.2%CVE-2026-57171HIGHTrestle is vulnerable to arbitrary file write via path traversal in author generate commands (Incomplete fix of CVE-2026-46345)EPSS 0.2%CVE-2022-42287MEDIUMNVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can upload and download arbitrary files under certain circEPSS 0.2%CVE-2025-43382MEDIUMA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.2,EPSS 0.2%CVE-2023-40383LOWA path handling issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.3. An app may be able to access user-sEPSS 0.2%CVE-2022-34429MEDIUMDell Hybrid Client below 1.8 version contains a Zip Slip Vulnerability in UI. A guest privilege attacker could potentially exploit this vulnEPSS 0.2%CVE-2024-31587MEDIUMSecuSTATION Camera V2.5.5.3116-S50-SMA-B20160811A and lower allows an unauthenticated attacker to download device configuration files via a EPSS 0.2%CVE-2026-12171HIGHauto-changelog: code execution via untrusted in-repository configuration (handlebarsSetup/plugins), plus argument injection, path traversal, and SSRFEPSS 0.2%CVE-2026-20625MEDIUMA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.4,EPSS 0.2%CVE-2025-59825MEDIUMastral-tokio-tar has a path traversal in tar extractionEPSS 0.2%CVE-2023-21456CRITICALPath traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uEPSS 0.2%CVE-2026-101051LOWCloudreve before 4.16.1 Path Traversal via Remote DownloadEPSS 0.2%CVE-2025-14311MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JMRI.This issue affects JMRI: before 5.13.3.EPSS 0.2%CVE-2025-43463MEDIUMA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.3,EPSS 0.2%CVE-2026-41433HIGHOpenTelemetry eBPF Instrumentation: Privileged Java agent injection allows arbitrary host file overwrite via untrusted TMPDIREPSS 0.2%CVE-2026-104805HIGHMitel MiVoice Office 400 Backup Restoration Arbitrary File Write Leading to Root Code ExecutionEPSS 0.2%CVE-2025-43417MEDIUMA path handling issue was addressed with improved logic. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2.EPSS 0.2%CVE-2026-30277HIGHAn arbitrary file overwrite vulnerability in PDF Reader App : TA/UTAX Mobile Print v3.7.2.251001 allows attackers to overwrite critical inteEPSS 0.2%CVE-2026-30279HIGHAn arbitrary file overwrite vulnerability in Squareapps LLC My Location Travel Timeline v11.80 allows attackers to overwrite critical internEPSS 0.2%