Weaknesses of type CWE-22

6,038 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2025-20277LOWCisco Unified Contact Center Express Path Traversal VulnerabilityEPSS 0.2%CVE-2026-54250MEDIUMK3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot DecompressionEPSS 0.2%CVE-2021-25361HIGHAn improper access control vulnerability in stickerCenter prior to SMR APR-2021 Release 1 allows local attackers to read or write arbitrary EPSS 0.2%CVE-2025-31248MEDIUMA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.5, mEPSS 0.2%CVE-2026-101036MEDIUMFLB-Music FLB-Music-Player createParsedTrack.ts path.join path traversalEPSS 0.2%CVE-2026-20615HIGHA path handling issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS SEPSS 0.2%CVE-2016-20048HIGHiSelect 1.4.0-2+b1 Local Buffer Overflow via key parameterEPSS 0.2%CVE-2026-102875HIGHVLC media player before 3.0.24 Path Traversal via skins2EPSS 0.2%CVE-2026-33922MEDIUMPath traversal in the Offline archives functionality of the local web interface in Arc before v2.7.0EPSS 0.2%CVE-2022-20453MEDIUMIn update of MmsProvider.java, there is a possible constriction of directory permissions due to a path traversal error. This could lead to lEPSS 0.2%CVE-2025-0542HIGHG DATA Management Server Local privilege escalationEPSS 0.2%CVE-2026-57471MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in KUNBUS RevPiPyLoadEPSS 0.2%CVE-2026-57472MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in KUNBUS RevPiPyLoadEPSS 0.2%CVE-2025-15066MEDIUMArbitrary File Download through Path Traversal in Innorix WPEPSS 0.2%CVE-2025-14617MEDIUMJehovahs Witnesses JW Library App org.jw.jwlibrary.mobile.activity.SiloContainer path traversalEPSS 0.2%CVE-2026-52886MEDIUMNotepad++: session.xml backupFilePath starts_with BypassEPSS 0.2%CVE-2026-8069HIGHPredatorSense V3: Local Privilege Escalation (LPE) vulnerabilityEPSS 0.2%CVE-2026-59948HIGHComposer: Arbitrary file write outside vendor via malicious transitive package nameEPSS 0.2%CVE-2026-20653MEDIUMA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.5 and iPadOSEPSS 0.2%CVE-2026-52875HIGHStreambert: Arbitrary Directory Creation and File Manipulation via Backup HandlerEPSS 0.2%