Fallos del tipo CWE-22

5969 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2025-55295MEDIUMqBit Manage Path Traversal VulnerabilityEPSS 0.5%CVE-2026-48126HIGHAlgernon: Host header path traversal in --domain mode reads files and runs Lua from parent dirEPSS 0.5%CVE-2025-67819MEDIUMAn issue was discovered in Weaviate OSS before 1.33.4. Due to a lack of validation of the fileName field in the transfer logic, an attacker EPSS 0.5%CVE-2026-41482HIGHFrappe: Possible Path Traversal and Local File Inclusion via Chrome PDF GeneratorEPSS 0.5%CVE-2025-64765MEDIUMAstro middleware authentication checks based on url.pathname can be bypassed via url encoded valuesEPSS 0.5%CVE-2025-25685HIGHAn issue was discovered in GL-INet Beryl AX GL-MT3000 v4.7.0. Attackers are able to download arbitrary files from the device's file system vEPSS 0.5%CVE-2025-46096MEDIUMDirectory Traversal vulnerability in solon v.3.1.2 allows a remote attacker to conduct XSS attacks via the solon-faas-luffy componentEPSS 0.5%CVE-2024-7631MEDIUMOpenshift-console: openshift console: path traversalEPSS 0.5%CVE-2026-93014HIGHRosarioSIS before 12.9 Path Traversal in File Deletion via filename ParameterEPSS 0.5%CVE-2026-46336HIGHManyfold: Authenticated Path Traversal via File RenameEPSS 0.5%CVE-2024-39688MEDIUMfishaudio/Bert-VITS2 Limited File Write in webui_preprocess.py generate_config functionEPSS 0.5%CVE-2022-46492MEDIUMnbnbk commit 879858451d53261d10f77d4709aee2d01c72c301 was discovered to contain an arbitrary file read vulnerability via the component /api/EPSS 0.5%CVE-2025-48130HIGHWordPress Spice Blocks plugin <= 2.0.7.4 - Arbitrary File Download vulnerabilityEPSS 0.5%CVE-2023-38012MEDIUMIBM Cloud Pak System directory traversalEPSS 0.5%CVE-2025-48273HIGHWordPress WP Job Portal plugin <= 2.3.2 - Arbitrary File Download VulnerabilityEPSS 0.5%CVE-2018-3770—A path traversal exists in markdown-pdf version <9.0.0 that allows a user to insert a malicious html code that can result in reading the locEPSS 0.5%CVE-2025-25684HIGHA lack of validation in the path parameter (/download) of GL-INet Beryl AX GL-MT3000 v4.7.0 allows attackers to download arbitrary files froEPSS 0.5%CVE-2026-15631HIGH@fastify/http-proxy vulnerable to prefix escape via WebSocket path traversalEPSS 0.5%CVE-2026-56273MEDIUMFlowise - Path Traversal in Vector Store basePath ParameterEPSS 0.5%CVE-2025-3445HIGHA Path Traversal "Zip Slip" vulnerability has been identified in mholt/archiver in Go. This vulnerability allows using a crafted ZIP file coEPSS 0.5%