Fallos del tipo CWE-22

5982 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2025-42906MEDIUMDirectory Traversal vulnerability in SAP Commerce CloudEPSS 0.4%CVE-2024-4556MEDIUMDirectory traversal vulnerability in NetIQ Access ManagerEPSS 0.4%CVE-2025-59566HIGHWordPress Workreap (theme's plugin) plugin <= 3.3.5 - Arbitrary File Deletion vulnerabilityEPSS 0.4%CVE-2026-41693HIGHi18next-fs-backend: Path traversal via unsanitised lng/ns allows arbitrary file read/overwriteEPSS 0.4%CVE-2026-77246HIGHMCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload PathEPSS 0.4%CVE-2025-68953HIGHCertain Frappe requests are vulnerable to Path TraversalEPSS 0.4%CVE-2026-42564HIGHjotty·page: Unauthenticated Path Traversal leads to sensitive file disclosure and session-token reuse impactEPSS 0.4%CVE-2026-49340HIGHgonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the hostEPSS 0.4%CVE-2025-47650MEDIUMWordPress Infility Global <= 2.15.06 - Arbitrary File Download vulnerabilityEPSS 0.4%CVE-2026-86251HIGHh3 before 1.15.9 Path Traversal via Double DecodingEPSS 0.4%CVE-2026-44301MEDIUMHugo: Node tool execution allows file system access outside the project directoryEPSS 0.4%CVE-2026-39306HIGHPraisonAI recipe registry pull path traversal writes files outside the chosen output directoryEPSS 0.4%CVE-2024-30417HIGHPath traversal vulnerability in the Bluetooth-based sharing module. Impact: Successful exploitation of this vulnerability may affect serviceEPSS 0.4%CVE-2026-50015HIGHpnpm: Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)EPSS 0.4%CVE-2026-41211HIGH`vite-plus/binding` has path traversal `downloadPackageManager()` that leads to writes outside of `VP_HOME`EPSS 0.4%CVE-2026-9145MEDIUMDatabase for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthenticated Arbitrary File Copy/Upload via Elementor Pro Form Upload Field 'raw_value'EPSS 0.4%CVE-2026-39305CRITICALArbitrary File Write / Path Traversal in Action OrchestratorEPSS 0.4%CVE-2026-103257HIGHn8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal via n8n NodeEPSS 0.4%CVE-2026-0394MEDIUMWhen dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or slash has been added EPSS 0.4%CVE-2026-44023HIGHDocling Core has unsafe remote filename resolutionEPSS 0.4%