Fallos del tipo CWE-22

5970 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-81030HIGHMage AI through 0.9.79 Arbitrary File Read via Unvalidated Path in browser_items EndpointEPSS 0.5%CVE-2026-11944MEDIUMopenSIS Classic 9.3 - Authenticated path traversal in SentMail attachment downloadEPSS 0.5%CVE-2026-63006MEDIUMZammad: HTML sanitizer API path allowlist bypass via interior path traversal in img src/srcsetEPSS 0.5%CVE-2026-43732MEDIUMA path handling issue was addressed with improved validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS TahoEPSS 0.5%CVE-2026-45775MEDIUMDiscourse: Cross-site backup access via path traversal in multisite local backupsEPSS 0.5%CVE-2026-78599MEDIUMStored Path Traversal in Kibana Leading to Unauthorized Deletion of Internal ResourcesEPSS 0.5%CVE-2025-12382HIGHPath Traversal Allows Remote Code Execution in AlgoSec Firewall AnalyzerEPSS 0.5%CVE-2026-13723MEDIUMDevelar's electron-builder allows arbitrary file overwriteEPSS 0.5%CVE-2025-66302MEDIUMGrav vulnerable to Path Traversal allowing server files backupEPSS 0.5%CVE-2026-24147MEDIUMNVIDIA Triton Inference Server contains a vulnerability in triton server where an attacker may cause an information disclosure by uploading EPSS 0.5%CVE-2025-14914HIGHIBM WebSphere Application Server Liberty Path TraversalEPSS 0.5%CVE-2026-64826HIGHrConfig < 8.2.13 Path Traversal File Read via FileDownloadControllerEPSS 0.5%CVE-2026-27884MEDIUMNetExec vulnerable to arbitrary file write via path traversal in spider_plus moduleEPSS 0.5%CVE-2026-31886CRITICALDagu has a Path Traversal via `dagRunId` in Inline DAG ExecutionEPSS 0.5%CVE-2024-32111MEDIUMWordPress core < 6.5.5 - Auth. Arbitrary .html File Read (Windows Only) vulnerabilityEPSS 0.5%CVE-2026-79306MEDIUMCyberPanel v1.9.1 contains a path traversal vulnerability in the compress method exposed through the /filemanager/controller endpoint. An auEPSS 0.5%CVE-2026-14783MEDIUMNousResearch hermes-agent skills_tool.py skill_view path traversalEPSS 0.5%CVE-2024-8685MEDIUMPath-Traversal vulnerability in Revolution PiEPSS 0.5%CVE-2026-11414CRITICALUnauthenticated File Exfiltration in Altium Enterprise Server Vault Service via Hard-coded Cryptographic Key and Path TraversalEPSS 0.5%CVE-2024-45312MEDIUMArbitrary language parameter can passed to `aspell` executable via spelling requests in overleafEPSS 0.5%