Weaknesses of type CWE-22

6,038 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-56377MEDIUMImageMagick - Policy Bypass via Incorrect Path ValidationEPSS 0.2%CVE-2016-20040HIGHTiEmu 3.03-nogdb+dfsg-3 Buffer Overflow via ROM ParameterEPSS 0.2%CVE-2016-20041HIGHYasr 0.6.9-5 Buffer Overflow via Command-line ParameterEPSS 0.2%CVE-2026-15392HIGHDBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted locationEPSS 0.2%CVE-2025-22240MEDIUMCVE-2025-22240 salt advisoryEPSS 0.2%CVE-2026-32677MEDIUMPath traversal for some gaudi-container-runtime before version 1.24.0 within Ring 3: User Applications may allow an escalation of privilege.EPSS 0.2%CVE-2026-38093LOWfile_picker (aka flutter_file_picker) for Flutter, all versions through 10.3.10, is vulnerable to path traversal (CWE-22) in its Android impEPSS 0.2%CVE-2026-54684HIGHjadx: XAPK archive entries with absolute paths can plant drop-in plugins and achieve code execution on the next jadx runEPSS 0.2%CVE-2026-47091MEDIUMClaude HUD 0.0.12 Path Traversal via transcript_pathEPSS 0.2%CVE-2026-35177MEDIUMPath traversal issue with zip.vim in VimEPSS 0.2%CVE-2026-49114MEDIUMONNX symlink-following and path-traversal arbitrary file writeEPSS 0.2%CVE-2026-15059MEDIUMsystemd-oomd: unprivileged users can terminate arbitrary processesEPSS 0.2%CVE-2025-20259MEDIUMCisco ThousandEyes Endpoint Agent for Windows Arbitrary File Write VulnerabilityEPSS 0.2%CVE-2026-9489HIGHNitroSense V3: Local Privilege Escalation (LPE) vulnerabilityEPSS 0.2%CVE-2026-52902MEDIUMAwxkit: path traversal via yaml !include directiveEPSS 0.2%CVE-2024-42187MEDIUMHCL BigFix Patch Download Plug-ins are affected by path traversal vulnerabilityEPSS 0.2%CVE-2026-42549MEDIUMFlight: Path traversal in `make:controller` CLI creates arbitrary directories outside project rootEPSS 0.2%CVE-2026-63266MEDIUMArbitrary file write via calcext:data-mappings, sql provider and Firebird backup functionalityEPSS 0.2%CVE-2026-47215MEDIUMSingularity: Incorrect path matching for 'limit container paths' directiveEPSS 0.2%CVE-2026-91801HIGHFoxit PDF Editor/Reader RichMedia Annotation Directory Traversal Remote Code Execution VulnerabilityEPSS 0.2%