Fallos del tipo CWE-22

6042 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-76369LOWPath Traversal through Automation Broker in Splunk SOAREPSS 0.4%CVE-2026-81847MEDIUMMAA-AI MaaMCP pipeline_tools.py load_pipeline path traversalEPSS 0.4%CVE-2026-97365MEDIUMchonkie-inc littrs lib.rs mount path traversalEPSS 0.4%CVE-2026-15687LOWPath traversal via non-tar copyDirectoryFromPodEPSS 0.4%CVE-2024-12429MEDIUMAn attacker who successfully exploited these vulnerabilities could grant read access to files. A vulnerability exists in the AC500 V3 versioEPSS 0.4%CVE-2020-10691MEDIUMAn archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. WheEPSS 0.4%CVE-2026-44788MEDIUMSharpCompress: Directory traversal via directory entries in WriteToDirectory (zip slip variant)EPSS 0.4%CVE-2026-35592MEDIUMpyLoad has an Incomplete Tar Path Traversal Fix in UnTar._safe_extractall via os.path.commonprefix BypassEPSS 0.4%CVE-2026-103293MEDIUMMPG < 4.2.3 - Editor+ Arbitrary File Read via Project ImportEPSS 0.4%CVE-2025-69904MEDIUMLinkstack v4.8.4 and earlier is vulnerable to Path Traversal, which allows an administrator to read arbitrary files on the server by manipulEPSS 0.4%CVE-2026-61431MEDIUMPraisonAI before 4.6.78 Path Traversal via ContextGathererEPSS 0.4%CVE-2026-104478HIGHFormwork before 2.3.13 Path Traversal via BackupController Download and DeleteEPSS 0.4%CVE-2026-28800MEDIUMNatro Macro: Malicious actions allowed through Discord RC Commands by any userEPSS 0.4%CVE-2025-29213MEDIUMA zip slip vulnerability in the component \service\migrate\MigrateForm.java of JEEWMS v3.7 allows attackers to execute arbitrary code via a EPSS 0.4%CVE-2026-32262MEDIUMCraft CMS has a Path Traversal Vulnerability in AssetsControllerEPSS 0.4%CVE-2026-16033HIGHArbitrary file read+write on host via templates/ symlink in malicious imageEPSS 0.4%CVE-2026-30848MEDIUMParse Server: `PagesRouter` path traversal allows reading files outside configured pages directoryEPSS 0.4%CVE-2025-64235MEDIUMWordPress Tuturn plugin < 3.6 - Arbitrary File Download vulnerabilityEPSS 0.4%CVE-2025-2830MEDIUMInformation Disclosure of /tmp directory listingEPSS 0.4%CVE-2026-66382MEDIUMAuthenticated users may write files outside the intended Artifactory work directoryEPSS 0.4%