Fallos del tipo CWE-22

5969 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-45017HIGHPython Liquid: Absolute paths escape filesystem loader search pathEPSS 0.5%CVE-2026-49233HIGHRoutinator cache path traversal using rogue rsync URIsEPSS 0.5%CVE-2026-44829HIGHGotenberg: Path traversal in zip entry name via Windows-style separators in upload filenameEPSS 0.5%CVE-2026-9166HIGHLFI in GIS Informatics' GisLab Laboratory Management SystemEPSS 0.5%CVE-2026-79407HIGHA path traversal vulnerability in the SPO extension of MetaGPT 0.8.1 allows an attacker to read arbitrary files via the FILE_NAME value usedEPSS 0.5%CVE-2026-39859MEDIUMLiquidJS has a renderFile() / parseFile() bypass configured root and allow arbitrary file readEPSS 0.5%CVE-2026-9690HIGHWordPress WP Media folder Addon plugin <= 4.0.1 - Arbitrary File Download vulnerabilityEPSS 0.5%CVE-2026-49061HIGHWordPress WPC Product Options for WooCommerce plugin <= 3.2.1 - Arbitrary File Download vulnerabilityEPSS 0.5%CVE-2026-73181HIGHWordPress Extra Product Options & Add-Ons for WooCommerce plugin < 7.6 - Arbitrary File Download vulnerabilityEPSS 0.5%CVE-2026-15585HIGHPath Traversal in AKIN Software's Wolvox9 ERPEPSS 0.5%CVE-2026-47368HIGHA malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to obtaiEPSS 0.5%CVE-2026-62663HIGHBanks: Arbitrary File Read via Path Traversal in Media Filters (image/audio/video/document)EPSS 0.5%CVE-2026-66476MEDIUMWordPress Easy Digital Downloads plugin <= 3.6.9 - Arbitrary File Deletion vulnerabilityEPSS 0.5%CVE-2026-65754HIGHJoomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extensionEPSS 0.5%CVE-2026-78275MEDIUMWordPress Fluent Boards Pro plugin <= 2.0.11 - Arbitrary File Deletion vulnerabilityEPSS 0.5%CVE-2026-65436MEDIUMWordPress Kirki plugin <= 6.0.13 - Arbitrary File Deletion vulnerabilityEPSS 0.5%CVE-2025-55295MEDIUMqBit Manage Path Traversal VulnerabilityEPSS 0.5%CVE-2026-75333HIGHyx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new File() for file systeEPSS 0.5%CVE-2026-57815HIGHWordPress Forminator plugin <= 1.55.0.2 - Arbitrary File Download vulnerabilityEPSS 0.5%CVE-2023-29502MEDIUMPTC Vuforia Studio Path TraversalEPSS 0.5%