Fallos del tipo CWE-22

5950 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-7314MEDIUMeiceblue spire-doc-mcp-server base.py get_doc_path path traversalEPSS 0.6%CVE-2026-81491MEDIUMboxpositron with-context-mcp index.ts project_folder path traversalEPSS 0.6%CVE-2025-23819HIGHWordPress WP Cloud plugin <= 1.4.3 - Arbitrary File Deletion vulnerabilityEPSS 0.6%CVE-2026-65607HIGHSiYuan before v3.7.2 Path Traversal via /export/temp/EPSS 0.6%CVE-2025-26753HIGHWordPress VideoWhisper Live Streaming Integration plugin <= 6.2 - Arbitrary File Download vulnerabilityEPSS 0.6%CVE-2026-61792HIGHWeblate path traversal allows a project administrator to read arbitrary files via App store metadata download (Incomplete Fix of CVE-2026-34242)EPSS 0.6%CVE-2025-14521MEDIUMbaowzh hfly download path traversalEPSS 0.6%CVE-2026-50186HIGH4gaBoards: Path Traversal leading to Arbitrary File Read and Deletion in Board ExportEPSS 0.6%CVE-2026-54687MEDIUMn8n-nodes-sqlite3: Path traversal via user-controlled database file path (db_path parameter)EPSS 0.6%CVE-2025-6853MEDIUMchatchat-space Langchain-Chatchat Backend upload_temp_docs path traversalEPSS 0.6%CVE-2025-6152MEDIUMSteel Browser files.routes.ts handleFileUpload path traversalEPSS 0.6%CVE-2026-92919HIGHadmin3 through 3.0.0 Arbitrary File Write via Path Traversal in Storage Upload FilenameEPSS 0.6%CVE-2026-41383MEDIUMOpenClaw < 2026.4.2 - Arbitrary Remote Directory Deletion via Mis-scoped Mirror Mode PathsEPSS 0.6%CVE-2026-92604HIGHScirius through 3.8.0 Arbitrary File Write via PCAP UploadEPSS 0.6%CVE-2025-8132MEDIUMyanyutao0402 ChanCMS utils.js delfile path traversalEPSS 0.6%CVE-2026-30914MEDIUMSFTPGo has a Path Traversal and Permission Bypass via Path Normalization DiscrepancyEPSS 0.6%CVE-2026-15450HIGHNEX-Forms <= 9.2.3 - Authenticated (Admin+) Arbitrary File Deletion via Path Traversal via 'location' ParameterEPSS 0.6%CVE-2026-81829MEDIUMSmallrye-jwt: quarkus-smallrye-jwt: smallrye-jwt: unauthenticated same-origin ssrf via unsanitized jwt kid header in awsalbkeyresolverEPSS 0.6%CVE-2022-44653HIGHA security agent directory traversal vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalatEPSS 0.6%CVE-2026-46337MEDIUMWWBN AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in `view/img/image404Raw.php`EPSS 0.6%