Fallos del tipo CWE-22

6043 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2025-58769LOWauth0-PHP: Improper File Type Handling in Bulk User ImportEPSS 0.4%CVE-2026-59280MEDIUMSpring Framework Path Traversal via Backslash in SpringTemplateLoaderEPSS 0.3%CVE-2026-55747MEDIUMPocketFlow - Path Traversal in pocketflow-coding-agent Cookbook Example File ToolsEPSS 0.3%CVE-2026-51883CRITICALThe knowledge base creation and document upload interfaces in Langchain-Chatchat 0.3.0;0.3.1 is vulnerable to path traversal. An attacker caEPSS 0.3%CVE-2026-51906CRITICALIn TaskingAI v0.3.0 in the DALL-E 3 image generation tool save_url_image function, a path traversal vulnerability allows attackers to write EPSS 0.3%CVE-2026-33171MEDIUMStatamic has a path traversal in file dictionary fieldtypeEPSS 0.3%CVE-2026-51875CRITICALIn Devika v1.0, the Feature Agent save_code_to_project function contains a path traversal vulnerability that allows attackers to write filesEPSS 0.3%CVE-2025-8522LOWgivanz Vvvebjs node.js save.php path traversalEPSS 0.3%CVE-2026-77260HIGHMCP Atlassian: Arbitrary local file READ via unconstrained file_path in upload_attachment (Confluence + Jira)EPSS 0.3%CVE-2026-7085LOWHBAI-Ltd Toonflow-app downloadApp Endpoint downloadApp.ts z.url path traversalEPSS 0.3%CVE-2025-58355HIGHSoft Serve is vulnerable to arbitrary file writing through its SSH APIEPSS 0.3%CVE-2025-7719MEDIUMSmallworld SWMFS Arbitrary File OpsEPSS 0.3%CVE-2026-50163HIGHoras-go: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution in `oras-go` tar extractionEPSS 0.3%CVE-2026-78312CRITICALPath Traversal in DIAEnergieEPSS 0.3%CVE-2026-90915HIGHJoomla! Core - [20260905] - Core - Arbitrary directory deletion via cache purge action in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3EPSS 0.3%CVE-2026-95588HIGHWordPress AcyMailing SMTP Newsletter plugin <= 11.0.5 - Arbitrary File Deletion vulnerabilityEPSS 0.3%CVE-2025-65076HIGHArbitrary File Read and Delete via Path Traversal in WaveStore ServerEPSS 0.3%CVE-2026-101889HIGHPrime Mover < 2.2.1 Path Traversal via wprime-config.jsonEPSS 0.3%CVE-2025-36598MEDIUMDell Avamar, versions prior to 19.12 with patch 338905, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path TraveEPSS 0.3%CVE-2026-88624CRITICALMissing path validation in the Worktree.remove component of openCode v1.18.26 allows attackers to execute arbitrary recursive directory deleEPSS 0.3%