Fallos del tipo CWE-22

5972 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-11426MEDIUMUnderConstructionPage PRO <= 5.76 - Authenticated (Subscriber+) Arbitrary File Read via template_thumbnail ParameterEPSS 0.5%CVE-2026-91940HIGHcrawl4ai before 0.9.3 Arbitrary File Write via PDFContentScrapingStrategyEPSS 0.5%CVE-2026-63667MEDIUMApostropheCMS: Arbitrary file read via import-export attachment-name path traversalEPSS 0.5%CVE-2025-6020HIGHLinux-pam: linux-pam directory traversalEPSS 0.5%CVE-2025-69128HIGHWordPress JobCareer theme <= 7.3 - Arbitrary File Deletion vulnerabilityEPSS 0.5%CVE-2019-25727CRITICALWordPress Plugin ad manager wd 1.0.11 Arbitrary File DownloadEPSS 0.5%CVE-2026-9856HIGHPath Traversal in huggingface/transformersEPSS 0.5%CVE-2023-41290MEDIUMQuFirewallEPSS 0.5%CVE-2026-54910HIGHFileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary filesEPSS 0.5%CVE-2026-75842HIGHArcadeDB before 26.8.1 Arbitrary File Read via LOAD CSVEPSS 0.5%CVE-2026-41655MEDIUMAdmidio: Path Traversal in ECard Preview Allows Reading Arbitrary Server Files Including Database CredentialsEPSS 0.5%CVE-2026-47179HIGHArcane: Authenticated Arbitrary Host File Read via Docker Compose Include Directives in ArcaneEPSS 0.5%CVE-2026-72697HIGHGrav CMS before 2.0.16 Path Traversal via media_directoryEPSS 0.5%CVE-2026-42275HIGHzrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/writeEPSS 0.5%CVE-2026-100707HIGHKyverno before 1.19.1 Namespace Isolation Bypass via Percent-Encoded PathEPSS 0.5%CVE-2026-71309HIGHrclone: Incomplete path validation allows backend root escape in serve resticEPSS 0.5%CVE-2026-41180HIGHPsiTransfer: Upload PATCH path traversal can create `config.<NODE_ENV>.js` and lead to code execution on restartEPSS 0.5%CVE-2026-2864MEDIUMfeng_ha_ha/megagao ssm-erp/production_ssm PictureController.java pictureDelete path traversalEPSS 0.5%CVE-2025-47415MEDIUMRECWAVE Filepath TraversalEPSS 0.5%CVE-2026-67246MEDIUMA path traversal vulnerability was found in the Wallpaper component of ADMEPSS 0.5%