Fallos del tipo CWE-22

5913 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-81560MEDIUMblackms aistack Static File server.ts path traversalEPSS 0.7%CVE-2025-12960MEDIUMSimple CSV Table <= 1.0.1 - Directory Traversal to Authenticated (Contributor+) Arbitrary File ReadEPSS 0.7%CVE-2024-5852MEDIUMWordPress File Upload <= 4.24.7 - Authenticated (Contributor+) Directory TraversalEPSS 0.7%CVE-2026-36726MEDIUMAn arbitrary file deletion vulnerability in the /api/delete-temp-license/{file} endpoint of bookcars v8.3 allows unauthenticated attackers tEPSS 0.7%CVE-2022-3940LOWlanyulei ferry task.go path traversalEPSS 0.7%CVE-2024-51998HIGHPath traversal using file URI scheme without supplying hostname in changedetection.ioEPSS 0.7%CVE-2026-15990HIGHFormidable Charts <= 2.0.1 - Unauthenticated Arbitrary File Read via 'frm_graph' ParameterEPSS 0.7%CVE-2024-7744MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Progress WS_FTP ServerEPSS 0.7%CVE-2026-54670CRITICALWeGIA: Unauthenticated Auth Bypass + Local File InclusionEPSS 0.7%CVE-2026-101067MEDIUMdbgate save-uploaded-file Endpoint files.js saveUploadedFile path traversalEPSS 0.7%CVE-2026-101066MEDIUMdbgate Archive Link Creation archive.js createLink path traversalEPSS 0.7%CVE-2024-44195HIGHA logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.1. An app may be able to read arbitrary files.EPSS 0.7%CVE-2026-63490HIGHHandlebars.java: Arbitrary file read in `SpringTemplateLoader` via URL-fragment suffix bypassEPSS 0.7%CVE-2026-85661CRITICALexcel-mcp-server 0.1.8 Arbitrary File Read/Write via stdio modeEPSS 0.7%CVE-2026-55607HIGHClaude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code ExecutionEPSS 0.7%CVE-2024-51751MEDIUMArbitrary file read with File and UploadButton components in GradioEPSS 0.7%CVE-2026-50180HIGHLangroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file readEPSS 0.7%CVE-2026-53872HIGHpicklescan - Arbitrary File Read via Unsafe Pickle DeserializationEPSS 0.7%CVE-2024-37043MEDIUMQTS, QuTS heroEPSS 0.7%CVE-2024-37046LOWQTS, QuTS heroEPSS 0.7%