Fallos del tipo CWE-22

5988 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-46338MEDIUMPyMdown Extensions: Regression in pymdownx.snippets reintroduces sibling-prefix path traversal bypass despite restrict_base_pathEPSS 0.4%CVE-2026-25635HIGHcalibre has a Path Traversal Leading to Arbitrary File Write and Potential Code ExecutionEPSS 0.4%CVE-2022-46305MEDIUMChangingTec ServiSign - Path TraversalEPSS 0.4%CVE-2025-28099MEDIUMopencms V2.3 is vulnerable to Arbitrary file read in src/main/webapp/view/admin/document/dataPage.jsp,EPSS 0.4%CVE-2025-12203MEDIUMgivanz Vvveb Code Editor functions.php sanitizeFileName path traversalEPSS 0.4%CVE-2025-7488MEDIUMJoeyBling SpringBoot_MyBatisPlus download path traversalEPSS 0.4%CVE-2025-7039LOWGlib: buffer under-read on glib through glib/gfileutils.c via get_tmp_file()EPSS 0.4%CVE-2025-8385MEDIUMZombify <= 1.7.5 - Authenticated (Subscriber+) Path Traversal to Arbitrary File ReadEPSS 0.4%CVE-2023-5327LOWSATO CL4NX-J Plus path traversalEPSS 0.4%CVE-2023-25341MEDIUMA Directory Traversal vulnerability in ladle dev server 2.5.1 and earlier allows an attacker on the same network to read files accessible toEPSS 0.4%CVE-2021-47979HIGHWordPress Plugin Backup and Restore 1.0.3 Arbitrary File DeletionEPSS 0.4%CVE-2025-31411MEDIUMWordPress Linet ERP-Woocommerce Integration plugin <= 3.5.12 - Arbitrary File Read/Deletion vulnerabilityEPSS 0.4%CVE-2026-2251CRITICALPath Traversal leading to Remote Code Execution (RCE)EPSS 0.4%CVE-2024-8510MEDIUMN-central Path TraversalEPSS 0.4%CVE-2026-24137MEDIUMsigstore legacy TUF client allows for arbitrary file writes with target cache path traversalEPSS 0.4%CVE-2026-29185LOW@backstage/integration: Potential reading of SCM URLs using built in tokenEPSS 0.4%CVE-2026-15955HIGHIBM® Data Server driver for JDBC and SQLJ could allow a remote attacker to perform an arbitrary file write due to improper validation of file pathsEPSS 0.4%CVE-2026-76614MEDIUMOpenEMR < 8.3.0 Path Traversal Information Disclosure via EDI Archive RestoreEPSS 0.4%CVE-2026-19303HIGHLangflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing componentsEPSS 0.4%CVE-2024-26292HIGHAuthenticated Arbitrary File Deletion affecting Avid NEXISEPSS 0.4%