Weaknesses of type CWE-22

6,036 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-65382MEDIUMA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27,EPSS 0.2%CVE-2026-25636HIGHcalibre has a Path Traversal Leading to Arbitrary File Corruption and Code ExecutionEPSS 0.2%CVE-2026-54557MEDIUMmise HTTP backend uses raw version path for install symlink destinationEPSS 0.2%CVE-2026-19368MEDIUMPV-Bhat gemsuite-mcp gemini_search unified-gemini.ts path traversalEPSS 0.2%CVE-2026-19046MEDIUMNocteDefensor LudusMCP ludus_environment_guides_search ludusEnvironmentGuidesSearch.ts path traversalEPSS 0.2%CVE-2026-14985HIGHCVE-2026-14985EPSS 0.2%CVE-2026-15526MEDIUMaugmnt augments-mcp-server scan_project_deps scan-project-deps.ts scanProjectDeps path traversalEPSS 0.2%CVE-2026-104853MEDIUMNx: Path traversal in nx migrate package-migrations extractionEPSS 0.2%CVE-2023-27409LOWA vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). A path traversal vulnerability was found in the `deviceinfo` EPSS 0.2%CVE-2026-19366MEDIUMNocteDefensor LudusMCP insert_creds_range_config insertCredsRangeConfig.ts path traversalEPSS 0.2%CVE-2026-15524MEDIUMalioshr memory-bank-mcp list-project-files-validation-factory.ts path traversalEPSS 0.2%CVE-2026-44171MEDIUMMariaDB: path traversal in mbstreamEPSS 0.2%CVE-2026-74859MEDIUMGnome-tweaks: path traversal in theme installerEPSS 0.2%CVE-2026-67397HIGHPath traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root.EPSS 0.2%CVE-2026-88790LOWproma-ai Proma File Preview Service file-preview-service.ts resolveTargetPath path traversalEPSS 0.2%CVE-2026-78638MEDIUMpeerigon unzip-crx/unzip-crx-3 Archive Extraction index.js unzip path traversalEPSS 0.2%CVE-2026-19270MEDIUMHulupeep mcp-ui-probe Journey/Usage JourneyStorage.ts usage_stats path traversalEPSS 0.2%CVE-2026-56844HIGHA vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges andEPSS 0.2%CVE-2026-19331MEDIUMbazylhorsey obsidian-mcp-server CanvasService.ts writeCanvas path traversalEPSS 0.2%CVE-2026-15749MEDIUMmastergo-design mastergo-magic-mcp mcp__C2d get-c2d.ts execute path traversalEPSS 0.2%