Weaknesses of type CWE-22

6,039 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2025-24268MEDIUMA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.4. AEPSS 0.1%CVE-2022-20505MEDIUMIn openFile of CallLogProvider.java, there is a possible permission bypass due to a path traversal error. This could lead to local escalatioEPSS 0.1%CVE-2026-101080LOWTencent AI-Infra-Guard File Access dir_actions.py startsWith path traversalEPSS 0.1%CVE-2026-20669MEDIUMA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Tahoe 26.3. An EPSS 0.1%CVE-2025-11565HIGHCWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause elevated systemEPSS 0.1%CVE-2026-41009MEDIUMLocal Blobstore may allow arbitrary reads/deletesEPSS 0.1%CVE-2026-22926HIGHOmnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability.EPSS 0.1%CVE-2026-0055MEDIUMIn createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC) into an invalid dirEPSS 0.1%CVE-2026-19743HIGHImproper Limitation of a Pathname to a Restricted Directory (Path Traversal) in TeamViewer Desktop ClientsEPSS 0.1%CVE-2026-57966MEDIUMSpice-vdagent: path traversal in file transfer via unsanitized filenameEPSS 0.1%CVE-2026-106109MEDIUMQuasar Framework: App Vite build cleanup can recursively remove unsafe configured output directoriesEPSS 0.1%CVE-2026-3223HIGHZip Slip leading to Arbitrary File Write and Privilege Escalation in Google Web DesignerEPSS 0.1%CVE-2025-54653HIGHPath traversal vulnerability in the virtualization file module. Successful exploitation of this vulnerability may affect the confidentialityEPSS 0.1%CVE-2025-54652HIGHPath traversal vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect the confidentialityEPSS 0.1%CVE-2025-53594MEDIUMQfinder Pro, Qsync, QVPNEPSS 0.1%CVE-2022-28784MEDIUMPath traversal vulnerability in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to list file names in arbitrary directory as EPSS 0.1%CVE-2021-25452MEDIUMAn improper input validation vulnerability in loading graph file in DSP driver prior to SMR Sep-2021 Release 1 allows attackers to perform pEPSS 0.1%CVE-2026-53766MEDIUMchrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing rootsEPSS 0.1%CVE-2025-48567HIGHIn multiple locations, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrecEPSS 0.1%CVE-2026-15953MEDIUMPath Traversal During Project Archive ImportEPSS 0.1%