Fallos del tipo CWE-22

5941 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-8113MEDIUM8421bit MiniClaw executeSkillScript kernel.ts isPathInside path traversalEPSS 0.6%CVE-2026-50540CRITICALKata Containers: Config Path Annotation Arbitrary File LoadingEPSS 0.6%CVE-2026-64836HIGHICEcoder through 8.1 Path Traversal via Ineffective File::check() ConfinementEPSS 0.6%CVE-2026-23850HIGHSiYuan vulnerable to arbitrary file readEPSS 0.6%CVE-2025-26905HIGHWordPress Estatik plugin <= 4.3.0 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2025-10951MEDIUMgeyang ml-logger server.py log_handler path traversalEPSS 0.6%CVE-2025-66905HIGHThe Takes web framework's TkFiles take thru 2.0-SNAPSHOT fails to canonicalize HTTP request paths before resolving them against the filesystEPSS 0.6%CVE-2026-74764CRITICALPath Traversal in TAR Archive Extraction Allows Arbitrary File Write in PandoraEPSS 0.6%CVE-2026-57856HIGHCockpit CMS Path Traversal via Bucket Name in Bucket File Storage APIEPSS 0.6%CVE-2026-27101MEDIUMDell Secure Connect Gateway (SCG) 5.0 Appliance and Application version(s) 5.28.00.xx to 5.32.00.xx, contain(s) an Improper Limitation of a EPSS 0.6%CVE-2026-55874HIGHSeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object readEPSS 0.6%CVE-2026-62677HIGHOmnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACEEPSS 0.6%CVE-2026-44542CRITICALFileBrowser Quantum: Unauthenticated Path Traversal in Public Share Delete Allows Arbitrary File DeletionEPSS 0.6%CVE-2025-30910HIGHWordPress CM Download Manager plugin <= 2.9.6 - Arbitrary File Deletion vulnerabilityEPSS 0.6%CVE-2026-47884CRITICALSpring Framework Improper Path Limitation in XsltViewEPSS 0.6%CVE-2025-27837CRITICALAn issue was discovered in Artifex Ghostscript before 10.05.0. Access to arbitrary files can occur through a truncated path with invalid UTFEPSS 0.6%CVE-2026-13054HIGHWatchGuard Firebox Arbitrary File Write via Path Traversal in Management Web UIEPSS 0.6%CVE-2023-44395MEDIUMAutolab has Path Traversal vulnerability in Assessment functionalityEPSS 0.6%CVE-2026-59555CRITICALWordPress Participants Database plugin <= 2.7.8.3 - Arbitrary File Deletion vulnerabilityEPSS 0.6%CVE-2024-55658HIGHSiYuan has an arbitrary file read and path traversal via /api/export/exportResourcesEPSS 0.6%