Fallos del tipo CWE-22

5988 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2025-65713MEDIUMHome Assistant Core before v2025.8.0 is vulnerable to Directory Traversal. The Downloader integration does not fully validate file paths durEPSS 0.4%CVE-2026-59974HIGHStanza: Zip Slip Path Traversal in Model/Resource ExtractionEPSS 0.4%CVE-2026-61625MEDIUMVictoriaMetrics vmrestore: path traversal via crafted backup part names escapes restore rootEPSS 0.4%CVE-2025-67115MEDIUMA path traversal vulnerability in /ftl/web/setup.cgi in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@230804184EPSS 0.4%CVE-2026-88344HIGHAn out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e. When an exact-length FlatBuffers schema buffer ends with EPSS 0.4%CVE-2026-78592HIGHImproper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthorized Deletion of Privileged ResourcesEPSS 0.4%CVE-2025-0332HIGHProgress UI for WinForms decompression path traversal vulnerabilityEPSS 0.4%CVE-2026-33238MEDIUMAVideo has a Path Traversal in listFiles.json.php that Enables Server Filesystem EnumerationEPSS 0.4%CVE-2026-78590HIGHImproper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthorized Deletion of Privileged ResourcesEPSS 0.4%CVE-2021-31421LOWThis vulnerability allows local attackers to delete arbitrary files on affected installations of Parallels Desktop 16.1.1-49141. An attackerEPSS 0.4%CVE-2026-76337MEDIUMPath Traversal through Splunk Web Static File Serving in Splunk EnterpriseEPSS 0.4%CVE-2026-35167HIGHKedro has a path traversal in versioned dataset loading via unsanitized version stringEPSS 0.4%CVE-2026-97323MEDIUMYunaiV/zhijiantianya ruoyi-vue-pro File Upload MpMaterialServiceImpl.java getOriginalFilename path traversalEPSS 0.4%CVE-2026-13693MEDIUMBit Form < 3.1.0 - Unauthenticated Arbitrary File Read via Path TraversalEPSS 0.4%CVE-2026-57079MEDIUMNet::BitTorrent versions before 2.1.0 for Perl write files outside the download directory via path traversal in peer-supplied metadataEPSS 0.4%CVE-2026-9468MEDIUMdazeb cline-mcp-memory-bank index.ts handleInitializeMemoryBank path traversalEPSS 0.4%CVE-2025-54715MEDIUMWordPress Barcode Scanner with Inventory & Order Manager Plugin <= 1.9.0 - Arbitrary File Download VulnerabilityEPSS 0.4%CVE-2026-9473MEDIUMc-rick jimeng-mcp api.ts generateVideo path traversalEPSS 0.4%CVE-2026-49342MEDIUMYARD static cache reads raw traversal paths before router sanitizationEPSS 0.4%CVE-2026-62680HIGHOrval: Generation-time SSRF + remote/local file inclusion via unrestricted $refEPSS 0.4%