Fallos del tipo CWE-22

5987 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-0964MEDIUMLibssh: improper sanitation of paths received from scp serversEPSS 0.4%CVE-2025-59819MEDIUMAuthenticated Arbitrary File Read via filepath parameterEPSS 0.4%CVE-2024-1163HIGHPath traversal vulnerability in mapshaperEPSS 0.4%CVE-2026-79705MEDIUMPodman: buildah: buildah/copier: directory escape via crafted tar symlinks when used outside buildah by non-root callersEPSS 0.4%CVE-2026-61432MEDIUMPraisonAI FastContext before 1.6.78 Path TraversalEPSS 0.4%CVE-2025-8023MEDIUMPath Traversal in Template Upload Allows Uploading Files Outside Target DirectoryEPSS 0.4%CVE-2026-11844MEDIUMIEI Integration Corp|iVEC-IEI Virtualization Edge Computer - Arbitrary File ReadEPSS 0.4%CVE-2026-48768CRITICALTypeBot: Unauthenticated arbitrary s3 object write in generate-upload-url via unsanitized fileNameEPSS 0.4%CVE-2026-52716MEDIUMWordPress WorkScout-Core plugin <= 1.7.11 - Arbitrary File Deletion vulnerabilityEPSS 0.4%CVE-2026-24488MEDIUMOpenEMR Vulnerable to Arbitrary File Exfiltration via Fax EndpointEPSS 0.4%CVE-2025-35053MEDIUMNewforma Info Exchange (NIX) arbitrary file read and deleteEPSS 0.4%CVE-2025-8559MEDIUMAll in One Music Player <= 1.3.1 - Authenticated (Contributor+) Path Traversal via theme ParameterEPSS 0.4%CVE-2025-27397MEDIUMA vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do not properly limit uEPSS 0.4%CVE-2025-40889HIGHPath traversal in Time Machine functionality in Guardian/CMC before 25.2.0EPSS 0.4%CVE-2023-41747MEDIUMSensitive information disclosure due to unauthenticated path traversal. The following products are affected: Acronis Cloud Manager (Windows)EPSS 0.4%CVE-2018-0123—A Path Traversal vulnerability in the diagnostic shell for Cisco IOS and IOS XE Software could allow an authenticated, local attacker to useEPSS 0.4%CVE-2025-0332HIGHProgress UI for WinForms decompression path traversal vulnerabilityEPSS 0.4%CVE-2025-40898HIGHPath traversal in Import Arc data archive functionality in Guardian/CMC before 25.5.0EPSS 0.4%CVE-2026-88344HIGHAn out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e. When an exact-length FlatBuffers schema buffer ends with EPSS 0.4%CVE-2025-65713MEDIUMHome Assistant Core before v2025.8.0 is vulnerable to Directory Traversal. The Downloader integration does not fully validate file paths durEPSS 0.4%