Fallos del tipo CWE-22

5892 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-61560CRITICAL@zereight/mcp-gitlab's unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and full account takeoverEPSS 0.8%CVE-2026-3795MEDIUMdoramart DoraCMS v1.js createFileBypath path traversalEPSS 0.8%CVE-2025-55526CRITICALn8n-workflows Main Commit ee25413 allows attackers to execute a directory traversal via the download_workflow function within api_server.pyEPSS 0.8%CVE-2023-32110HIGHWordPress JupiterX theme <= 3.0.0 - Auth. Local File Inclusion vulnerabilityEPSS 0.8%CVE-2026-57571CRITICALCrawl4AI arbitrary file write via download filename path traversalEPSS 0.8%CVE-2025-66051MEDIUMPath traversal in Vivotek IP7137 camerasEPSS 0.8%CVE-2026-61372HIGHApache Jena Fuseki: Web requests using SPARQL Update can escape file restrictionsEPSS 0.8%CVE-2026-3067MEDIUMHummerRisk Archive Extraction CommandUtils.java extractZip path traversalEPSS 0.8%CVE-2026-47896HIGHApache Lucene.Net: Unauthenticated arbitrary file read on the Lucene.Net.Replicator replication serverEPSS 0.8%CVE-2024-42468MEDIUMPath traversal (CometVisu)EPSS 0.8%CVE-2026-32232HIGHZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlinkEPSS 0.8%CVE-2025-25652HIGHIn Eptura Archibus 2024.03.01.109, the "Run script" and "Server File" components of the "Database Update Wizard" are vulnerable to directoryEPSS 0.8%CVE-2025-6439CRITICALWooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File DeletionEPSS 0.8%CVE-2023-27700HIGHMuYuCMS v2.2 was discovered to contain an arbitrary file deletion vulnerability via the component /accessory/picdel.html.EPSS 0.8%CVE-2025-51475MEDIUMArbitrary File Overwrite (AFO) in superagi.controllers.resources.upload in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to oveEPSS 0.8%CVE-2025-40629HIGHPath Traversal vulnerability in PNETLabEPSS 0.8%CVE-2025-34320CRITICALBASIS BBj < 25.00 Unauthenticated Arbitrary File Read RCEEPSS 0.8%CVE-2025-67742LOWIn JetBrains TeamCity before 2025.11 path traversal was possible via file uploadEPSS 0.8%CVE-2026-17556HIGHPath traversal in GitHub Enterprise Server allowed unauthenticated deletion of instance storage via the X-GitHub-Request-Id headerEPSS 0.8%CVE-2022-4511MEDIUMRainyGao DocSys path traversalEPSS 0.8%