Weaknesses of type CWE-22

6,036 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-29050MEDIUMmelange has Path Traversal When Resolving External Pipelines via Unvalidated pipeline[].usesEPSS 0.2%CVE-2026-55569MEDIUMaqua: Archive extraction in aqua follows attacker-planted symlinks, allowing writes outside the install directoryEPSS 0.2%CVE-2026-64756MEDIUMA path handling issue was addressed with improved validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS SequoEPSS 0.2%CVE-2026-84624MEDIUMA permissions issue was addressed with improved path validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOEPSS 0.2%CVE-2026-84534MEDIUMA path handling issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS GEPSS 0.2%CVE-2026-55846MEDIUMAllure: Path Traversal in Allure Report HTTP Server Allows Arbitrary File ReadEPSS 0.2%CVE-2024-20805LOWPath traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.2EPSS 0.2%CVE-2026-21991MEDIUMA DTrace component, dtprobed, allows arbitrary file creation through crafted USDT provider names.EPSS 0.2%CVE-2026-95667MEDIUMMISP Installer Log and FIFO Created World-Readable, Exposing Sensitive CredentialsEPSS 0.2%CVE-2026-28457MEDIUMOpenClaw < 2026.2.14 - Path Traversal in Sandbox Skill Mirroring via Name ParameterEPSS 0.2%CVE-2026-60089MEDIUMPraisonAI before 1.6.78 Path Traversal via config.tomlEPSS 0.2%CVE-2026-5656HIGHImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in WiresharkEPSS 0.2%CVE-2026-32061MEDIUMOpenClaw < 2026.2.17 - Arbitrary File Read via $include Directive Path TraversalEPSS 0.2%CVE-2026-63225MEDIUMRedocly CLI: Path traversal when using `split` commandEPSS 0.2%CVE-2026-9108MEDIUMStudio 5000 Logix Designer® – Multiple VulnerabilitiesEPSS 0.2%CVE-2026-47712LOWDulwich doesn't sanitize commit subjects in `porcelain.format_patch`EPSS 0.2%CVE-2026-49406MEDIUMDeno: BYONM module resolution allows `package.json` main path traversal to bypass `--allow-read` restrictionsEPSS 0.2%CVE-2025-3722NONEA path traversal vulnerability in System Information Reporter (SIR) 1.0.3 and prior allowed an authenticated high privileged user to issue EPSS 0.2%CVE-2026-73657MEDIUMTrigger.dev: Cross-tenant payload poisoning via packet write + replayEPSS 0.2%CVE-2026-19324MEDIUMHelloGGX shadcn-vue-mcp callback-server.ts fs.promises.readFile path traversalEPSS 0.2%