Fallos del tipo CWE-22

5987 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2025-29865HIGH: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TAGFREE X-Free Uploader XFU allows Path TrEPSS 0.4%CVE-2025-5380MEDIUMashinigit 天青一白 XueShengZhuSu 学生住宿管理系统 Image File Upload upload path traversalEPSS 0.4%CVE-2026-28786MEDIUMOpen WebUI vulnerable to Path Traversal in `POST /api/v1/audio/transcriptions`EPSS 0.4%CVE-2026-48798HIGHSSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP FilenamesEPSS 0.4%CVE-2026-63134MEDIUMMalcolm's Path Traversal in Archive Extraction Allows Arbitrary Directory CreationEPSS 0.4%CVE-2026-85015MEDIUMUnlimited Elements For Elementor < 2.0.21 - Authenticated Arbitrary File Write via Path TraversalEPSS 0.4%CVE-2025-10777MEDIUMJSC R7 R7-Office Document Server downloadas path traversalEPSS 0.4%CVE-2026-34978MEDIUMOpenPrinting CUPS: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (and clobbering of job.cache)EPSS 0.4%CVE-2026-104871MEDIUMAngular SSR: Path Traversal to Sibling Directories in CommonEngine on WindowsEPSS 0.4%CVE-2025-6774MEDIUMgooaclok819 sublinkX template.go AddTemp path traversalEPSS 0.4%CVE-2024-37825MEDIUMAn issue in EnvisionWare Computer Access & Reservation Control SelfCheck v1.0 (fixed in OneStop 3.2.0.27184 Hotfix May 2024) allows unauthenEPSS 0.4%CVE-2025-7518MEDIUMRSFirewall! <= 1.1.42 - Authenticated (Admin+) Arbitrary File ReadEPSS 0.4%CVE-2026-92812HIGHdecap-server Path Traversal via Sibling Directory Prefix MatchingEPSS 0.4%CVE-2025-1915HIGHImproper Limitation of a Pathname to a Restricted Directory in DevTools in Google Chrome on Windows prior to 134.0.6998.35 allowed an attackEPSS 0.4%CVE-2026-16335HIGHDataStage on Cloud Pak for Data has several vulnerabilities due to open source softwareEPSS 0.4%CVE-2024-11615MEDIUMEnvolve Plugin <= 1.0 - Unauthenticated Language File DeletionEPSS 0.4%CVE-2026-82112MEDIUMhoutini-ai houtini-lm code_task_files index.ts path traversalEPSS 0.4%CVE-2026-31978MEDIUMmotionEye: Arbitrary File Read via Path Traversal in Picture/Movie Preview EndpointEPSS 0.4%CVE-2026-54150MEDIUMnext-video: Unauthenticated arbitrary file read via /api/video request handlerEPSS 0.4%CVE-2026-25062MEDIUMOutline Affected an Arbitrary File Read via Path Traversal in JSON ImportEPSS 0.4%