Fallos del tipo CWE-22

5992 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-104417MEDIUMGhost 1.20.0 before 6.64.0 Path Traversal via Locale SettingEPSS 0.4%CVE-2026-20916HIGHBIG-IQ iControl REST vulnerabilityEPSS 0.4%CVE-2020-1737HIGHA flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip moEPSS 0.4%CVE-2023-41057MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in hyper-bump-itEPSS 0.4%CVE-2026-67295MEDIUMFreeRDP before 3.29.0 Path Traversal via drive redirectionEPSS 0.4%CVE-2025-8406MEDIUMPath Traversal in zenml-io/zenmlEPSS 0.4%CVE-2025-14293MEDIUMWP Job Portal <= 2.4.0 - Authenticated (Subscriber+) Arbitrary File ReadEPSS 0.4%CVE-2025-68862HIGHWordPress Woo File Dropzone plugin <= 1.1.7 - Arbitrary File Deletion vulnerabilityEPSS 0.4%CVE-2025-68921HIGHSteelSeries Nahimic 3 1.10.7 allows Directory traversal.EPSS 0.4%CVE-2025-27098MEDIUMUnwanted access to the entire file system vulnerability due to a missing check in `staticFiles` HTTP handler in graphql-meshEPSS 0.4%CVE-2026-77193HIGHeesy_ID2WP – Publish InDesign HTML5 <= 1.0.3 - Unauthenticated Path Traversal to Arbitrary File Read via 'id2wp_path' Query ParameterEPSS 0.4%CVE-2026-22661HIGHprompts.chat Path Traversal via Skill File HandlingEPSS 0.4%CVE-2022-4773LOWcloudsync LocalFilesystemConnector.java getItem path traversalEPSS 0.4%CVE-2026-23942MEDIUMSFTP root escape via component-agnostic prefix check in ssh_sftpdEPSS 0.4%CVE-2025-61649LOWUserInfoCard: Check that performing user has permission to view log entries for number of past blocksEPSS 0.4%CVE-2026-13224HIGHFireware OS Path Traversal in WebUI Management Agent Allows Arbitrary Local File ReadEPSS 0.4%CVE-2024-46327MEDIUMAn issue in the Http_handle object of VONETS VAP11G-300 v3.3.23.6.9 allows attackers to access sensitive files via a directory traversal.EPSS 0.4%CVE-2026-86071LOWJunrar: LocalFolderExtractor mkdir escape allows directory creation outside extraction rootEPSS 0.4%CVE-2023-2110HIGHObsidian Local File DisclosureEPSS 0.4%CVE-2026-97242MEDIUMWordPress WEBO MCP plugin <= 3.0.18 - Arbitrary File Deletion vulnerabilityEPSS 0.4%