Fallos del tipo CWE-22

5929 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-54293HIGHNLTK: URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File ReadEPSS 0.6%CVE-2026-65092HIGHNVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7 REST network policy.EPSS 0.6%CVE-2025-25284HIGHPath Traversal and Local File Read via VRT (Virtual Format) in ZOO-Project WPS ImplementationEPSS 0.6%CVE-2023-37461MEDIUMPath traversal in metersphereEPSS 0.6%CVE-2026-56673HIGHComfyUI: Path traversal in LoadImage via the /prompt API allows arbitrary file existence probing and image exfiltrationEPSS 0.6%CVE-2026-53481CRITICALDell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1EPSS 0.6%CVE-2021-22685MEDIUMCassia Networks Access Controller Path TraversalEPSS 0.6%CVE-2023-45688—Information leak via path traversal in Titan MFT and Titan SFTP serversEPSS 0.6%CVE-2018-25181HIGHMusicco 2.0.0 Arbitrary Directory Download via Path TraversalEPSS 0.6%CVE-2025-12060HIGHKeras keras.utils.get_file Utility Path Traversal VulnerabilityEPSS 0.6%CVE-2023-45823HIGHArbitrary file read in Artifact HubEPSS 0.6%CVE-2024-43434HIGHMoodle: csrf risk in feedback non-respondents reportEPSS 0.6%CVE-2025-13816MEDIUMmoxi159753 Mogu Blog v2 ZIP File unzipFile FileOperation.unzip path traversalEPSS 0.6%CVE-2026-82635HIGHPake arbitrary file write via unsanitized download_file filenameEPSS 0.6%CVE-2024-41971HIGHWAGO: Arbitrary File Overwrite in Multiple DevicesEPSS 0.6%CVE-2026-85731HIGHoras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir)EPSS 0.6%CVE-2026-66755MEDIUMApache Tika: Arbitrary Local File Read in ISArchiveParserEPSS 0.6%CVE-2024-43138MEDIUMWordPress Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 4.2.1 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2024-52964MEDIUMAn Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.EPSS 0.6%CVE-2024-54132MEDIUMGitHub CLI allows downloading malicious GitHub Actions workflow artifact to result in path traversal vulnerabilityEPSS 0.6%