Fallos del tipo CWE-22

5974 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-14973CRITICALPath Traversal in IBM Desktop AppEPSS 0.5%CVE-2026-54550HIGHIzPack: Path Traversal in UnpackerBase allows writing files outside the installation directory via malicious pack entriesEPSS 0.5%CVE-2022-22054MEDIUMASUS RT-AX56U - Path TraversalEPSS 0.5%CVE-2026-6961HIGHCVE-2026-6961: Path traversal via unsanitized FileInfo.Name in Mattermost federation syncEPSS 0.5%CVE-2023-40264MEDIUMAn issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated path traversal in the userEPSS 0.5%CVE-2025-64108HIGHCursor's Sensitive File Modification can Lead to NTFS Path QuirksEPSS 0.5%CVE-2026-28705MEDIUMGitea repository dumps write release assets using unsafe path namesEPSS 0.5%CVE-2026-69153MEDIUMPostCSS: incomplete fix of CVE-2026-45623 — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unsetEPSS 0.5%CVE-2026-50024MEDIUMGitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via a malicious .git serverEPSS 0.5%CVE-2023-47221MEDIUMPhoto StationEPSS 0.4%CVE-2023-34217HIGHSecond Order Command-injection Vulnerability in the Certificate-delete FunctionEPSS 0.4%CVE-2026-39407MEDIUMHono has a middleware bypass via repeated slashes in serveStaticEPSS 0.4%CVE-2026-32733HIGHHalloy has a file transfer path traveral vulnerabilityEPSS 0.4%CVE-2025-60223HIGHWordPress WPBot Pro Wordpress Chatbot plugin <= 13.6.5 - Arbitrary File Deletion vulnerabilityEPSS 0.4%CVE-2025-46559MEDIUMMisskey Directory Traversal Vulnerability in AiScript via `Mk:api`EPSS 0.4%CVE-2026-54708HIGHAuthenticated Remote Code Execution via Path Traversal in FreePBX Backup ModuleEPSS 0.4%CVE-2026-39408MEDIUMHono has a path traversal in toSSG() allows writing files outside the output directoryEPSS 0.4%CVE-2026-55699MEDIUMpnpm: reserved bin name deletes PNPM_HOME during global removeEPSS 0.4%CVE-2025-11607MEDIUMharry0703 MoneyPrinterTurbo API Endpoint music.py upload_music path traversalEPSS 0.4%CVE-2024-54535MEDIUMA path handling issue was addressed with improved logic. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, visionOS 2.1, EPSS 0.4%