Weaknesses of type CWE-22

6,038 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-57472MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in KUNBUS RevPiPyLoadEPSS 0.2%CVE-2026-52886MEDIUMNotepad++: session.xml backupFilePath starts_with BypassEPSS 0.2%CVE-2025-15066MEDIUMArbitrary File Download through Path Traversal in Innorix WPEPSS 0.2%CVE-2025-14617MEDIUMJehovahs Witnesses JW Library App org.jw.jwlibrary.mobile.activity.SiloContainer path traversalEPSS 0.2%CVE-2026-59948HIGHComposer: Arbitrary file write outside vendor via malicious transitive package nameEPSS 0.2%CVE-2026-52875HIGHStreambert: Arbitrary Directory Creation and File Manipulation via Backup HandlerEPSS 0.2%CVE-2026-20653MEDIUMA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.5 and iPadOSEPSS 0.2%CVE-2026-56377MEDIUMImageMagick - Policy Bypass via Incorrect Path ValidationEPSS 0.2%CVE-2026-15392HIGHDBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted locationEPSS 0.2%CVE-2016-20041HIGHYasr 0.6.9-5 Buffer Overflow via Command-line ParameterEPSS 0.2%CVE-2026-32677MEDIUMPath traversal for some gaudi-container-runtime before version 1.24.0 within Ring 3: User Applications may allow an escalation of privilege.EPSS 0.2%CVE-2025-22240MEDIUMCVE-2025-22240 salt advisoryEPSS 0.2%CVE-2016-20040HIGHTiEmu 3.03-nogdb+dfsg-3 Buffer Overflow via ROM ParameterEPSS 0.2%CVE-2026-54684HIGHjadx: XAPK archive entries with absolute paths can plant drop-in plugins and achieve code execution on the next jadx runEPSS 0.2%CVE-2026-38093LOWfile_picker (aka flutter_file_picker) for Flutter, all versions through 10.3.10, is vulnerable to path traversal (CWE-22) in its Android impEPSS 0.2%CVE-2026-47091MEDIUMClaude HUD 0.0.12 Path Traversal via transcript_pathEPSS 0.2%CVE-2026-35177MEDIUMPath traversal issue with zip.vim in VimEPSS 0.2%CVE-2026-49114MEDIUMONNX symlink-following and path-traversal arbitrary file writeEPSS 0.2%CVE-2026-15059MEDIUMsystemd-oomd: unprivileged users can terminate arbitrary processesEPSS 0.2%CVE-2025-20259MEDIUMCisco ThousandEyes Endpoint Agent for Windows Arbitrary File Write VulnerabilityEPSS 0.2%