Fallos del tipo CWE-22

5950 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2025-6854MEDIUMchatchat-space Langchain-Chatchat files path traversalEPSS 0.6%CVE-2025-24965HIGH.krun_config.json symlink attack creates or overwrites file on the host in crunEPSS 0.6%CVE-2026-53571HIGHVite: `server.fs.deny` bypass on Windows alternate pathsEPSS 0.6%CVE-2025-54433HIGHBugsink is vulnerable to Path Traversal attacks via event_id in ingestionEPSS 0.6%CVE-2025-4898MEDIUMSourceCodester Student Result Management System Logo File update_system.php unlink path traversalEPSS 0.6%CVE-2024-32703HIGHWordPress ARForms plugin <= 6.4 - Subscriber+ Arbitrary File Deletion vulnerabilityEPSS 0.6%CVE-2024-52600MEDIUMStatamic CMS has Path Traversal in Asset UploadEPSS 0.6%CVE-2026-44943MEDIUMremote limited file-write as root via discovery in open-iscsiEPSS 0.6%CVE-2025-48387HIGHtar-fs has issue where extract can write outside the specified dir with a specific tarballEPSS 0.6%CVE-2022-0436HIGHPath Traversal in gruntjs/gruntEPSS 0.6%CVE-2024-37462HIGHWordPress Ultimate Bootstrap Elements for Elementor plugin <= 1.4.2 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2026-45279MEDIUMNextcloud: Limited path traversal via template API if using `{lang}` in configEPSS 0.6%CVE-2025-65815MEDIUMA lack of security checks in the file import process of AB TECHNOLOGY Document Reader: PDF, DOC, PPT v65.0 allows attackers to execute a dirEPSS 0.6%CVE-2026-39847CRITICALEmmett has a path traversal in internal assets handlerEPSS 0.6%CVE-2024-31451MEDIUMLimited file write in routes.py (GHSL-2023-250)EPSS 0.6%CVE-2025-65814MEDIUMA lack of security checks in the file import process of RHOPHI Analytics LLP Office App-Edit Word v6.4.1 allows attackers to execute a direcEPSS 0.6%CVE-2025-54443CRITICALImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allowEPSS 0.6%CVE-2023-27311MEDIUMNetApp Blue XP Connector versions prior to 3.9.25 expose information via a directory listing. A new Connector architecture resolves this issEPSS 0.6%CVE-2024-37224HIGHWordPress SP Project & Document Manager plugin <= 4.71 - Directory Traversal vulnerabilityEPSS 0.6%CVE-2026-73620HIGHGitPython before 3.1.57 Arbitrary File Overwrite and ReadEPSS 0.6%