Weaknesses of type CWE-22

6,022 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2023-5097HIGHImproper Input Validation vulnerability in HYPR Workforce Access on Windows allows Path Traversal.This issue affects Workforce Access: beforEPSS 0.2%CVE-2026-96419MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in WiresharkEPSS 0.2%CVE-2026-45224MEDIUMCrabbox < 0.9.0 Path Traversal via Islo Provider Workspace ResolutionEPSS 0.2%CVE-2026-29780MEDIUMeml_parser: Path Traversal in Official Example Script Leading to Arbitrary File WriteEPSS 0.2%CVE-2026-35570HIGHOpenClaude has Sandbox Bypass via Early-Exit Logic Flaw that Allows Path TraversalEPSS 0.2%CVE-2026-30853MEDIUMcalibre has a Path Traversal Leading to Arbitrary File WriteEPSS 0.2%CVE-2026-84201MEDIUMappium-mcp-server through 0.1.61 Path Traversal in write_file and write_files_batchEPSS 0.2%CVE-2026-43989HIGHJunoClaw: upload_wasm accepted arbitrary filesystem paths without validationEPSS 0.2%CVE-2026-49497MEDIUMGhidra < 12.1 - Path Traversal via .gnu_debuglink in DWARF External Debug File ResolutionEPSS 0.2%CVE-2026-28482HIGHOpenClaw < 2026.2.12 - Path Traversal via Unsanitized sessionId and sessionFile ParametersEPSS 0.2%CVE-2025-3465HIGHPath Traversal VulnerabilityEPSS 0.2%CVE-2026-39973HIGHApktool: Path Traversal to Arbitrary File WriteEPSS 0.2%CVE-2026-43723HIGHA path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.EPSS 0.2%CVE-2026-58203MEDIUMNestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_sizeEPSS 0.2%CVE-2026-13748MEDIUMSnowflake CLI Arbitrary Local File Read and Exfiltration Through Improper File Path RestrictionEPSS 0.2%CVE-2026-85456MEDIUMMOOS-IvP through 24.8.1 alog Splitting Path Traversal on WindowsEPSS 0.2%CVE-2026-50181HIGHLangroid: Path traversal in the file tools allows read/write outside configured current directoryEPSS 0.2%CVE-2026-47144MEDIUMShamefile has an arbitrary file read via shamefile.yaml in shame nextEPSS 0.2%CVE-2023-20943HIGHIn clearApplicationUserData of ActivityManagerService.java, there is a possible way to remove system files due to a path traversal error. ThEPSS 0.2%CVE-2022-36400MEDIUMPath traversal in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow anEPSS 0.2%