Fallos del tipo CWE-22

5972 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-75115HIGHJoomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOtheme Pro 2.3.0-5.0.40EPSS 0.5%CVE-2026-66491HIGHJoomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3EPSS 0.5%CVE-2026-44973HIGHBilly: Path traversal vulnerabilitiesEPSS 0.5%CVE-2026-65765MEDIUMJoomla Extension - phoca.cz - Path traversal vulnerability in Phoca Commander 1.0.0-6.1.1EPSS 0.5%CVE-2026-46724MEDIUMPath Traversal in extension "Faceted Search" (ke_search)EPSS 0.5%CVE-2026-76576MEDIUMyangzongzhuan RuoYi-Vue Common Download Endpoint CommonController.java resourceDownload path traversalEPSS 0.5%CVE-2026-19829MEDIUM648540858 wvp-GB28181-pro Log File Download Endpoint LogController.java path traversalEPSS 0.5%CVE-2026-94049MEDIUM06ketan slideshot renderer.ts render_slides path traversalEPSS 0.5%CVE-2026-22334HIGHWordPress Woocommerce Book Price plugin <= 1.3 - Arbitrary File Download vulnerabilityEPSS 0.5%CVE-2026-7086MEDIUMHBAI-Ltd Toonflow-app Storyboard Export replaceUrl.ts updateStoryboardUrl path traversalEPSS 0.5%CVE-2025-69131HIGHWordPress WordPress & WooCommerce Scraper Plugin, Import Data from Any Site plugin <= 1.0.7 - Arbitrary File Download vulnerabilityEPSS 0.5%CVE-2026-94037MEDIUM00Kisumi00 mcp-file-analyzer analyze_csv_data MCP tool main.py ControlFlowNode path traversalEPSS 0.5%CVE-2026-94046MEDIUM0215AndrewFeng ACE-MCP MCP Tool getFileSnippet.ts get_file_snippet path traversalEPSS 0.5%CVE-2026-25691MEDIUMA improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5,EPSS 0.5%CVE-2026-22876HIGHPath Traversal vulnerability exists in multiple Network Cameras TRIFORA 3 series provided by TOA Corporation. If this vulnerability is exploEPSS 0.5%CVE-2026-42867MEDIUMLangflow: Path Traversal in Knowledge Bases API via Creation EndpointEPSS 0.5%CVE-2026-8643MEDIUMpip can extract console_scripts and gui_scripts outside installation directoryEPSS 0.5%CVE-2020-3236MEDIUMCisco Enterprise NFV Infrastructure Software Path Traversal VulnerabilityEPSS 0.5%CVE-2026-41690HIGHPrototype pollution and path traversal in i18next-http-middleware via user-controlled language and namespace parametersEPSS 0.5%CVE-2026-56066MEDIUMWordPress ShortPixel Adaptive Images plugin <= 3.11.4 - Arbitrary File Deletion vulnerabilityEPSS 0.5%