Fallos del tipo CWE-22

5988 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-42593MEDIUMGotenberg: Arbitrary PDF read via stampExpression and watermarkExpression in merge, split, and convert routesEPSS 0.4%CVE-2026-11846HIGHIEI Integration Corp|iVEC-IEI Virtualization Edge Computer - Arbitrary File DeletionEPSS 0.4%CVE-2026-100689HIGHGitPython before 3.1.62 Path Traversal via gitmodules pathEPSS 0.4%CVE-2026-19306HIGHLangflow is vulnerable to arbitrary local file read due to path traversal in ChatInput, bundle FileInput, and GitExtractor componentsEPSS 0.4%CVE-2026-35484MEDIUMtext-generation-webui has a Path Traversal in load_preset() — .yaml file read without authenticationEPSS 0.4%CVE-2025-64757LOWAstro Development Server is Vulnerable to Arbitrary Local File ReadEPSS 0.4%CVE-2020-12499HIGHPHOENIX CONTACT PLCnext Engineer version 2020.3.1 and earlier: Improper path sanitation vulnerability.EPSS 0.4%CVE-2025-8151MEDIUMHT Mega – Absolute Addons For Elementor <= 2.9.1 - Authenticated (Author+) Path Traversal to Limited Arbitrary CSS File ActionsEPSS 0.4%CVE-2025-8749MEDIUMPath traversal vulnerability in MiR robot software via API requestsEPSS 0.4%CVE-2026-22460HIGHWordPress FormGent plugin <= 1.7.0 - Arbitrary File Deletion vulnerabilityEPSS 0.4%CVE-2025-53375MEDIUMDokploy allows attackers to read any file that the Traefik process user can accessEPSS 0.4%CVE-2025-64230HIGHWordPress Filr plugin <= 1.2.10 - Arbitrary File Deletion vulnerabilityEPSS 0.4%CVE-2026-39406MEDIUM@hono/node-server has a middleware bypass via repeated slashes in serveStaticEPSS 0.4%CVE-2026-1186HIGHPath Traversal in EAP LegislatorEPSS 0.4%CVE-2025-11540CRITICALPath Traversal vulnerability in Sharp Display Solutions projectors allows a attacker may access and read any files within the projector.EPSS 0.4%CVE-2025-31174MEDIUMPath traversal vulnerability in the DFS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.EPSS 0.4%CVE-2025-63918MEDIUMPDFPatcher executable does not validate user-supplied file paths, allowing directory traversal attacks allowing attackers to upload arbitrarEPSS 0.4%CVE-2026-57961MEDIUMphpMyFAQ - Authenticated Path Traversal in PDF Export via concatenatePaths FunctionEPSS 0.4%CVE-2026-65920MEDIUMDiffusers Path Traversal via weight_map Arbitrary File ReadEPSS 0.4%CVE-2026-46338MEDIUMPyMdown Extensions: Regression in pymdownx.snippets reintroduces sibling-prefix path traversal bypass despite restrict_base_pathEPSS 0.4%