Fallos del tipo CWE-22

5991 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-56839HIGHPraisonAI Code agent tools fail open without a workspace boundaryEPSS 0.4%CVE-2026-65939MEDIUMWhatsUp Gold versions prior to 26.0.2 contain an arbitrary file write vulnerability in the LogToFile action handler.EPSS 0.4%CVE-2025-10245MEDIUMDisplay Painéis TGA Galeria rename path traversalEPSS 0.4%CVE-2026-55668MEDIUMFile Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scopeEPSS 0.4%CVE-2024-43395HIGHCraftOS-PC 2's improperly sanitizied paths cause filesystem escape (Windows)EPSS 0.4%CVE-2026-21878HIGHBACnet Stack Improperly Limits Pathnames to a Restricted DirectoryEPSS 0.4%CVE-2025-12626MEDIUMjeecgboot jeewx-boot WxActGoldeneggsPrizesController.java getImgUrl path traversalEPSS 0.4%CVE-2026-2818HIGHZip Slip Path Traversal in Snapshot Archive Extraction (Windows-Specific)EPSS 0.4%CVE-2026-0604MEDIUMFastDup <= 2.7 - Authenticated (Contributor+) Path Traversal via 'dir_path' REST ParameterEPSS 0.4%CVE-2026-84667HIGHJenkins ThinBackup Plugin 2.1.4 and earlier allows overwriting the plugin's backup configuration through Stapler data binding, allowing attaEPSS 0.4%CVE-2024-23773HIGHAn issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An Arbitrary file delete vulnerability exists in the KSchedulEPSS 0.4%CVE-2025-41073HIGHPath Traversal in Gandia Integra Total by TESIEPSS 0.4%CVE-2026-22677MEDIUMHermes WebUI < 0.51.44 Path Traversal via Session Import EndpointEPSS 0.4%CVE-2025-69380HIGHWordPress Upload Files Anywhere plugin <= 2.8 - Arbitrary File Download vulnerabilityEPSS 0.4%CVE-2023-51651MEDIUMPotential URI resolution path traversal in the AWS SDK for PHPEPSS 0.4%CVE-2023-49801MEDIUMLif Auth Server vulnerable to uncontrolled data in path expression EPSS 0.4%CVE-2026-55495MEDIUMCloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner AccountEPSS 0.4%CVE-2025-7452MEDIUMkone-net go-chat Endpoint file_controller.go GetFile path traversalEPSS 0.4%CVE-2026-57716MEDIUMWordPress Broadcast Live Video plugin <= 7.2.4 - Arbitrary File Deletion vulnerabilityEPSS 0.4%CVE-2026-39245MEDIUMdecompress before 4.2.2 contains an improper path containment check that enables directory traversal and arbitrary file write. The safeMakeDEPSS 0.4%