Weaknesses of type CWE-22

6,022 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-47144MEDIUMShamefile has an arbitrary file read via shamefile.yaml in shame nextEPSS 0.2%CVE-2022-44564HIGHHuawei Aslan Children's Watch has a path traversal vulnerability. Successful exploitation may allow attackers to access or modify protected EPSS 0.2%CVE-2026-52872HIGHStreambert: Local File Exfiltration and Overwrite via Subtitle file: ProtocolEPSS 0.2%CVE-2025-22241MEDIUMCVE-2025-22241 salt advisoryEPSS 0.2%CVE-2026-84541MEDIUMAn input validation issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macEPSS 0.2%CVE-2026-86910MEDIUMA permissions issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS TahoEPSS 0.2%CVE-2026-18953MEDIUMImproper limitation of a pathname to a restricted directory in aws-transform-mcp-serverEPSS 0.2%CVE-2026-86902MEDIUMA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27,EPSS 0.2%CVE-2026-50207HIGHLocal Modem Manipulation via Binder InterfacesEPSS 0.2%CVE-2026-29051MEDIUMmelange has Path Traversal via .PKGINFO in --persist-lint-resultsEPSS 0.2%CVE-2026-22927HIGHOmnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability.EPSS 0.2%CVE-2023-41825LOW A path traversal vulnerability was reported in the Motorola Ready For application that could allow a local attacker to access local files. EPSS 0.2%CVE-2026-53925HIGHGlances: Arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configurationEPSS 0.2%CVE-2026-62383MEDIUMnltk IPIPANCorpusReader Symlink Arbitrary File ReadEPSS 0.2%CVE-2026-77091HIGHDataCube Security Feature BypassEPSS 0.2%CVE-2026-78249MEDIUMA path traversal vulnerability exists in the web management interface of multiple Multifunction Devices and Printers, including Apeos C4571 EPSS 0.2%CVE-2026-13103HIGHA potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow aEPSS 0.2%CVE-2026-29050MEDIUMmelange has Path Traversal When Resolving External Pipelines via Unvalidated pipeline[].usesEPSS 0.2%CVE-2026-60088MEDIUMPraisonAI before 4.6.78 Path Traversal via Custom CommandsEPSS 0.2%CVE-2024-20805LOWPath traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.2EPSS 0.2%