Fallos del tipo CWE-22

5925 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-33227MEDIUMApache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ: Improper Limitation of a Pathname to a Restricted Classpath DirectoryEPSS 0.7%CVE-2024-52771CRITICALDedeBIZ v6.3.0 was discovered to contain an arbitrary file deletion vulnerability via the component /admin/file_manage_view.EPSS 0.7%CVE-2025-0859MEDIUMPost and Page Builder by BoldGrid <= 1.27.6 - Path Traversal to Authenticated (Contributor+) Arbitrary File Read via template_via_url FunctionEPSS 0.7%CVE-2024-4297MEDIUMHGiga iSherlock - Arbitrary File DownloadEPSS 0.7%CVE-2026-44336CRITICALPraisonAI MCP `tools/call` path-traversal and RCE via Python `.pth` injectionEPSS 0.7%CVE-2026-25928MEDIUMOpenEMR Vulnerable to Path Traversal When Zipping DICOM FoldersEPSS 0.7%CVE-2026-5957MEDIUMEmailKit <= 1.6.5 - Authenticated (Author+) Arbitrary File Read via 'emailkit-editor-template' REST ParameterEPSS 0.7%CVE-2024-4296MEDIUMHGiga iSherlock - Arbitrary File DownloadEPSS 0.7%CVE-2026-35397HIGHjupyter-server path traversal allows access to sibling directories sharing root_dir name prefixEPSS 0.7%CVE-2023-5938HIGHPath traversal via 'zip slip' in Arc before v1.6.0EPSS 0.7%CVE-2023-2909HIGHA Directory traversal vulnerability was found on EZ Sync service of ADMEPSS 0.7%CVE-2024-24122CRITICALA remote code execution vulnerability in the project management of Wanxing Technology's Yitu project which allows an attacker to use the expEPSS 0.7%CVE-2026-15204MEDIUMTOTOLINK X5000R OpenVPN Export cstecgi.cgi exportOvpn path traversalEPSS 0.7%CVE-2024-2023MEDIUMFolders <= 3.0 and Folders Pro <= 3.0.2 - Directory Traversal via handle_folders_file_uploadEPSS 0.7%CVE-2024-8585MEDIUMLEARNING DIGITAL Orca HCM - Arbitrary File DownloadEPSS 0.7%CVE-2026-76639HIGHUnitree G1 EDU 1.5.2 Unauthenticated RCE via DDS Bridge and Path TraversalEPSS 0.7%CVE-2024-52481HIGHWordPress Jobify theme < 4.3.0 - Unauthenticated Arbitrary File Read vulnerabilityEPSS 0.7%CVE-2024-43011MEDIUMAn arbitrary file deletion vulnerability exists in the admin/del.php file at line 62 in ZZCMS 2023 and earlier. Due to insufficient validatiEPSS 0.7%CVE-2025-41229HIGHVMware Cloud Foundation Directory Traversal VulnerabilityEPSS 0.7%CVE-2026-15074HIGH@fastify/static vulnerable to route guard bypass via path traversalEPSS 0.7%