Fallos del tipo CWE-22

5929 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-30462MEDIUMA path traversal vulnerability in the Blocks module of Daylight Studio FuelCMS v1.5.2 allows attackers to execute a directory traversal.EPSS 0.6%CVE-2025-4187MEDIUMUserPro - Community and User Profile WordPress Plugin <= 5.1.10 - Unauthenticated Arbitrary File ReadEPSS 0.6%CVE-2026-28792CRITICALCross-Origin File Exfiltration via CORS Misconfiguration + Path Traversal in TinaCMSEPSS 0.6%CVE-2023-37932MEDIUMAn improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in FortiVoiceEntreprise version 7.0EPSS 0.6%CVE-2025-58755HIGHMONAI has path traversal issue that may lead to arbitrary file writesEPSS 0.6%CVE-2026-7235MEDIUMErlichLiu claude-agent-sdk-master route.ts path traversalEPSS 0.6%CVE-2026-5013MEDIUMelecV2 elecV2P :key path.join path traversalEPSS 0.6%CVE-2026-7403MEDIUMgeldata gel-mcp server.py fetch_rule path traversalEPSS 0.6%CVE-2026-34524HIGHSillyTavern: Path traversal in `/api/chats/export` and `/api/chats/delete` allows arbitrary file read/delete within user data rootEPSS 0.6%CVE-2026-8115MEDIUMgyoridavid short-video-maker REST API rest.ts path traversalEPSS 0.6%CVE-2026-7059MEDIUM666ghj MiroFish Query Parameter simulation.py get_simulation_posts path traversalEPSS 0.6%CVE-2026-7588MEDIUMggerve coding-standards-mcp server.py get_best_practices path traversalEPSS 0.6%CVE-2023-0092MEDIUMAn authenticated user who has read access to the juju controller model, may construct a remote request to download an arbitrary file from thEPSS 0.6%CVE-2026-7132MEDIUMcode-projects Online Lot Reservation System download.php readfile path traversalEPSS 0.6%CVE-2024-24908MEDIUMDell PowerProtect DM5500 version 5.15.0.0 and prior contain an Arbitrary File Delete via Path Traversal vulnerability. A remote attacker witEPSS 0.6%CVE-2026-5014MEDIUMelecV2 elecV2P Wildcard log path.join path traversalEPSS 0.6%CVE-2026-7589MEDIUMghantakiran splunk-mcp-integration CSV Export csv_export.py create_csv_export path traversalEPSS 0.6%CVE-2022-47506HIGHSolarWinds Platform Directory Traversal VulnerabilityEPSS 0.6%CVE-2026-49128HIGHMusic Player Daemon < 0.24.11 Path Traversal via LocalStorage URI HandlingEPSS 0.6%CVE-2026-7217MEDIUMDeepractice PromptX Document File index.ts read_pdf absolute path traversalEPSS 0.6%