Fallos del tipo CWE-22

5970 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-88069CRITICALPath traversal in Pandora archive extractor allows arbitrary file writes outside the extraction directory in pandora analysisEPSS 0.5%CVE-2024-45709MEDIUMSolarWinds Web Help Desk Local File Read VulnerabilityEPSS 0.5%CVE-2022-4982HIGHDBLTek GoIP-1 vGHSFVT-1.1-67-5 Unauthenticated LFIEPSS 0.5%CVE-2026-87984CRITICALAn arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an attacker to create or overwrite files outside EPSS 0.5%CVE-2026-81845MEDIUMarben-adm mcp-sequential-thinking Import Session/Export Session server.py export_session path traversalEPSS 0.5%CVE-2026-76611MEDIUMJoomla Extension - yootheme.com - Unauthenticated arbitrary directory listing via the Gallery element in Zoo < 4.1.66EPSS 0.5%CVE-2026-42888MEDIUMAudiobookshelf: Path Traversal vulnerability in the audiobookshelf projectEPSS 0.5%CVE-2026-76606CRITICALJoomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2EPSS 0.5%CVE-2026-19594HIGHPath Traversal and HTTP Parameter Pollution in Snowflake Python API (snowflake.core) Allow Confused-Deputy Privilege EscalationEPSS 0.5%CVE-2024-39651HIGHWordPress WooCommerce PDF Vouchers plugin < 4.9.5 - Unauthenticated Arbitrary File Deletion vulnerabilityEPSS 0.5%CVE-2026-4741HIGHPath Traversal Vulnerability in TeamJCD/JoyConDroidEPSS 0.5%CVE-2026-75887HIGHOpenshift/console: openshift/console: unauthenticated path traversal in i18n locale handlerEPSS 0.5%CVE-2023-49788HIGHImproper handling of browser-side provided input in richdocuments path handlingEPSS 0.5%CVE-2026-44593HIGHesm.sh: Legacy Route Path Traversal Can Lead to RCEEPSS 0.5%CVE-2026-78085MEDIUMJoomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4EPSS 0.5%CVE-2026-19038MEDIUMMonomythDevelopment la-forge-mcp screenshot_element Tool index.ts screenshotElement path traversalEPSS 0.5%CVE-2026-53777HIGHPerry < 0.5.1159 Path Traversal via ArtifactReady WebSocketEPSS 0.5%CVE-2026-16888LOWVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2025-10232MEDIUM299ko FileManagerAPIController.php delete path traversalEPSS 0.5%CVE-2026-42315HIGHpyLoad: Path Traversal via Package Folder Name in set_package_dataEPSS 0.5%