Fallos del tipo CWE-22

5974 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2025-4893MEDIUMjammy928 CoinExchange_CryptoExchange_Java File Upload Endpoint UploadFileUtil.java uploadLocalImage path traversalEPSS 0.5%CVE-2026-40605MEDIUMTautulli Vulnerable to Authenticated Path Traversal in Cache Deletion APIEPSS 0.5%CVE-2026-43872MEDIUMactual-server has a path traversal vulnerabilityEPSS 0.5%CVE-2025-4868MEDIUMmerikbest ecommerce-spring-reactjs File Upload Endpoint admin path traversalEPSS 0.5%CVE-2026-47682HIGHCVAT: Missing path-containment validation in multiple entry points allows arbitrary path writesEPSS 0.5%CVE-2025-59336MEDIUMRelative Path Traversal in LuanoxEPSS 0.5%CVE-2026-39405CRITICALFrappe has Path Transversal via SCORMEPSS 0.5%CVE-2024-33869MEDIUMAn issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript docuEPSS 0.5%CVE-2026-81659HIGHFlowintel Note PDF Export Allows Arbitrary Local File Read via Pandoc/XeLaTeX ProcessingEPSS 0.5%CVE-2026-9035MEDIUMMultiple vulnerabilities in Aspera applications.EPSS 0.5%CVE-2026-7646MEDIUMLangflow is affected by security vulnerabilities in Model Context Protocol featuresEPSS 0.5%CVE-2026-9153MEDIUMArbitrary File Read in Rapid7 InsightConnect Sed PluginEPSS 0.5%CVE-2025-64184HIGHDosage vulnerable to Directory Traversal through crafted HTTP responsesEPSS 0.5%CVE-2026-70424MEDIUMDell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path TraversaEPSS 0.5%CVE-2026-91012CRITICALApache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege EscalationEPSS 0.5%CVE-2026-54468MEDIUMDell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a path traversal vulnerability. A low privileged attacker with remoteEPSS 0.5%CVE-2026-30234MEDIUMOpenProject BIM BCF XML Import: <Snapshot> Path Traversal Leads to Arbitrary Local File Read (AFR)EPSS 0.5%CVE-2025-66300HIGHGrav is vulnerable to Arbitrary File ReadEPSS 0.5%CVE-2026-67247HIGHA path traversal vulnerability was found in the IHM Log handling of ADMEPSS 0.5%CVE-2026-14973CRITICALPath Traversal in IBM Desktop AppEPSS 0.5%