Fallos del tipo CWE-22

5975 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-87030HIGHTanium addressed a path traversal vulnerability in Comply.EPSS 0.4%CVE-2026-14194MEDIUMPath Traversal Allows Arbitrary File Download in Bilin Software's HUMANIST Digital Human ResourcesEPSS 0.4%CVE-2026-1703LOWLimited path traversal when installing wheel archivesEPSS 0.4%CVE-2026-75797HIGHAI Engine 3.3.3 - 3.7.1 - Subscriber+ Arbitrary File Read via 'url' ParameterEPSS 0.4%CVE-2026-47277MEDIUMRuntipi: Unauthenticated arbitrary file read through app-store logo symlinksEPSS 0.4%CVE-2026-81275MEDIUMWordPress Youzify plugin <= 1.3.7 - Arbitrary File Download vulnerabilityEPSS 0.4%CVE-2026-42679MEDIUMWordPress Classified Listing plugin <= 5.3.8 - Arbitrary File Download vulnerabilityEPSS 0.4%CVE-2026-65582HIGHWordPress AI Hub theme <= 1.3.10 - Arbitrary File Download vulnerabilityEPSS 0.4%CVE-2026-14468HIGHPath traversal allows arbitrary file read in Terraform Enterprise containerEPSS 0.4%CVE-2026-42129HIGHPath traversal in the Loki data source pluginEPSS 0.4%CVE-2026-35605MEDIUMFile Browser has an access rule bypass via HasPrefix without trailing separator in path matchingEPSS 0.4%CVE-2026-4542MEDIUMSSCMS layerImage Endpoint LayerImageController.Submit.cs path traversalEPSS 0.4%CVE-2025-66278LOWFile Station 5EPSS 0.4%CVE-2026-77266MEDIUMMCP Atlassian: Path traversal in upload_attachment allows arbitrary file read and exfiltration via MCP tool callEPSS 0.4%CVE-2026-82599MEDIUMSeaCMS Avatar Upload member.php unlink path traversalEPSS 0.4%CVE-2025-48017CRITICALImproper Limitation of a Pathname to a Restricted DirectoryEPSS 0.4%CVE-2026-84702HIGHfacefusion before 3.7.0 Path Traversal via Job IdentifierEPSS 0.4%CVE-2026-82603MEDIUMSeaCMS Comment Cache member.php del_pl path traversalEPSS 0.4%CVE-2024-11481HIGHA vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API. This leads to improper handling of path traverEPSS 0.4%CVE-2026-55092HIGHTrivy: Path traversal via a crafted vulnerability database or other downloaded artifactsEPSS 0.4%