Fallos del tipo CWE-22

5940 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-64731CRITICALA path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious appEPSS 0.6%CVE-2025-54446CRITICALImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allowEPSS 0.6%CVE-2026-41193CRITICALFreeScout has Zip Slip path traversal in module installation that allows arbitrary file write leading to RCEEPSS 0.6%CVE-2025-20051CRITICALArbitrary file read via block duplication in Mattermost BoardsEPSS 0.6%CVE-2024-3980CRITICALThe MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that are used in filesystEPSS 0.6%CVE-2025-27085MEDIUMArbitrary File Download Vulnerabilities in Web-Based Management Interface of AOS-10 GW and AOS-8 Controller/Mobility ConductorEPSS 0.6%CVE-2026-40258CRITICALGramps Web API has Zip Slip Path Traversal in Media Archive ImportEPSS 0.6%CVE-2025-54438CRITICALImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allowEPSS 0.6%CVE-2024-35308HIGHPost-auth Arbitrary File Read in the Server Plugins SectionEPSS 0.6%CVE-2026-28676HIGHOpenSift: Insufficient path containment checks in storage helpers could allow path traversal-style file operationsEPSS 0.6%CVE-2024-26129MEDIUMPrestashop vulnerable to path disclosure in JavaScript variableEPSS 0.6%CVE-2026-42213MEDIUMSolidCAM-GPPL-IDE: Path traversal in `inc` directive enables file probing and NTLM-hash leakEPSS 0.6%CVE-2023-32974HIGHQTS, QuTS hero, QuTScloudEPSS 0.6%CVE-2024-11585HIGHWP Hide & Security Enhancer <= 2.5.1 - Missing Authorization to Unauthenticated Arbitrary File Contents DeletionEPSS 0.6%CVE-2024-20528LOWCisco Identity Services Engine Path Traversal VulnerabilityEPSS 0.6%CVE-2024-37089CRITICALWordPress Consulting Elementor Widgets plugin <= 1.3.0 - Unauthenticated Local File Inclusion vulnerabilityEPSS 0.6%CVE-2024-51958MEDIUMDirectory traversal vulnerability in the admin api for service thumbnailsEPSS 0.6%CVE-2026-45623HIGHPostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS commentsEPSS 0.6%CVE-2026-8113MEDIUM8421bit MiniClaw executeSkillScript kernel.ts isPathInside path traversalEPSS 0.6%CVE-2026-2692MEDIUMCoCoTeaNet CyreneAdmin Image getAvatar path traversalEPSS 0.6%