Fallos del tipo CWE-22

5972 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2023-43070MEDIUM Dell SmartFabric Storage Software v1.4 (and earlier) contains a Path Traversal Vulnerability in the HTTP interface. A remote authenticated EPSS 0.5%CVE-2025-14753HIGHIBM Cloud Pak for Data is vulnerable to path traversalEPSS 0.5%CVE-2026-39307HIGHPraisonAI has an Arbitrary File Write (Zip Slip) in Templates ExtractionEPSS 0.5%CVE-2026-59924MEDIUMMistune: Arbitrary File Read via Include directive path traversalEPSS 0.5%CVE-2026-25640HIGHPydantic AI affected by Stored XSS via Path Traversal in Web UI CDN URLEPSS 0.5%CVE-2025-3547MEDIUMfrdel Agent-Zero get_work_dir_files path traversalEPSS 0.5%CVE-2026-18899HIGHLangflow is affected by multiple authentication bypass, path traversal, authorization, and server-side request forgery vulnerabilitiesEPSS 0.5%CVE-2026-41887MEDIUMFlarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)EPSS 0.5%CVE-2025-51463HIGHPath Traversal in restore_run_backup() in AIM 3.28.0 allows remote attackers to write arbitrary files to the server's filesystem via a craftEPSS 0.5%CVE-2026-32808HIGHpyLoad: Arbitrary File Deletion via Path Traversal during Encrypted 7z Password VerificationEPSS 0.5%CVE-2026-5203MEDIUMCMS Made Simple UserGuide Module XML Import class.UserGuideImporterExporter.php _copyFilesToFolder path traversalEPSS 0.5%CVE-2024-35081HIGHLuckyFrameWeb v3.5.2 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter in the fileDownload methoEPSS 0.5%CVE-2026-44566HIGHOpen WebUI: Arbitrary File Upload and Path TraversalEPSS 0.5%CVE-2026-34603HIGH@tinacms/graphql's Media Endpoints Can Escape the Media Root via Symlinks or JunctionsEPSS 0.5%CVE-2023-54403HIGHYonyou U8 CRM Arbitrary File Read via getemaildata.phpEPSS 0.5%CVE-2026-15700MEDIUMDedeCMS Album Publishing Feature zip.class.php ExtractFile path traversalEPSS 0.5%CVE-2026-6957HIGHPath traversal in Mattermost Legal Hold plugin via unsanitized file name from federated peer allows arbitrary file write.EPSS 0.5%CVE-2026-23888MEDIUMpnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip)EPSS 0.5%CVE-2025-53358MEDIUMkotaemon Vulnerable to Path Traversal via Link UploadEPSS 0.5%CVE-2025-11016MEDIUMkalcaddle kodbox index.class.php fileOut path traversalEPSS 0.5%