Weaknesses of type CWE-22

6,039 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-52902MEDIUMAwxkit: path traversal via yaml !include directiveEPSS 0.2%CVE-2026-9489HIGHNitroSense V3: Local Privilege Escalation (LPE) vulnerabilityEPSS 0.2%CVE-2024-42187MEDIUMHCL BigFix Patch Download Plug-ins are affected by path traversal vulnerabilityEPSS 0.2%CVE-2026-63266MEDIUMArbitrary file write via calcext:data-mappings, sql provider and Firebird backup functionalityEPSS 0.2%CVE-2026-42549MEDIUMFlight: Path traversal in `make:controller` CLI creates arbitrary directories outside project rootEPSS 0.2%CVE-2026-47215MEDIUMSingularity: Incorrect path matching for 'limit container paths' directiveEPSS 0.2%CVE-2026-91801HIGHFoxit PDF Editor/Reader RichMedia Annotation Directory Traversal Remote Code Execution VulnerabilityEPSS 0.2%CVE-2022-20449MEDIUMIn writeApplicationRestrictionsLAr of UserManagerService.java, there is a possible overwrite of system files due to a path traversal error. EPSS 0.2%CVE-2026-82427HIGHApache Storm Nimbus: Path Traversal as the Supervisor User via Unsanitised Blobstore Map Local NameEPSS 0.2%CVE-2022-50956MEDIUMWordPress Plugin amministrazione-aperta 3.7.3 Local File ReadEPSS 0.2%CVE-2026-49356LOWBabel: Arbitrary File Read via sourceMappingURL Comment in @babel/coreEPSS 0.2%CVE-2026-88014MEDIUMrclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespaceEPSS 0.2%CVE-2026-48785MEDIUMApptainer: Incorrect path matching for 'limit container paths' directiveEPSS 0.1%CVE-2026-45380LOWbit7z: Path Traversal via Null Byte Injection from `gcount()` Off-by-One in `restoreSymlink()`EPSS 0.1%CVE-2024-47292MEDIUMPath traversal vulnerability in the Bluetooth module Impact: Successful exploitation of this vulnerability may affect service confidentialitEPSS 0.1%CVE-2025-59890HIGHImproper input sanitization in the file archives upload functionality of Eaton Galileo software allows traversing paths which could lead intEPSS 0.1%CVE-2026-9789HIGHNitroSense V3: Security Vulnerability InformationEPSS 0.1%CVE-2026-101295HIGHOc-mirror: oc-mirror: path traversal / arbitrary file write in operator catalog image extractionEPSS 0.1%CVE-2026-51882CRITICALThe OpenAI-compatible file upload endpoint `/v1/files` in Langchain-Chatchat 0.3.0 is vulnerable to path traversal. An attacker can write fiEPSS 0.1%CVE-2025-24268MEDIUMA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.4. AEPSS 0.1%