Fallos del tipo CWE-22

6044 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2025-65076HIGHArbitrary File Read and Delete via Path Traversal in WaveStore ServerEPSS 0.3%CVE-2026-22762MEDIUMDell Avamar Server and Avamar Virtual Edition, versions prior to 19.10 SP1 with CHF338912, contain an Improper Limitation of a Pathname to aEPSS 0.3%CVE-2026-58171LOWVibe-Trading < 0.1.10 - Path Traversal via Swarm Run IdentifierEPSS 0.3%CVE-2023-26243HIGHAn issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The decryption binary used toEPSS 0.3%CVE-2021-39143MEDIUMPath Traversal in spinnakerEPSS 0.3%CVE-2025-15470MEDIUMEleganzo <= 1.2 - Authenticated (Subscriber+) Arbitrary Directory DeletionEPSS 0.3%CVE-2026-66063MEDIUMgoshs has a Path Traversal issueEPSS 0.3%CVE-2026-16955MEDIUMAI Engine < 3.6.6 - Subscriber+ Arbitrary File Read via Audio TranscriptionEPSS 0.3%CVE-2026-42885MEDIUMAudiobookshelf: Path prefix bypass in filesystem existence check leaks out-of-scope file existenceEPSS 0.3%CVE-2026-7807HIGHSmarterTools SmarterMail < Build 9560 Server Local File Inclusion via the /api/v1/report/summary/{type} APIEPSS 0.3%CVE-2025-53505MEDIUMGroup-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a path traversal vulnerability. If this vulneraEPSS 0.3%CVE-2026-48789MEDIUMAnythingLLM: Windows path containment bypass in document folder routeEPSS 0.3%CVE-2022-50953MEDIUMWordPress Plugin admin-word-count-column 2.2 Local File ReadEPSS 0.3%CVE-2025-13876MEDIUMRareprob HD Video Player All Formats App com.rocks.music.videoplayer path traversalEPSS 0.3%CVE-2026-54613MEDIUMVvveb: Path Traversal in Revision Backup Reader/Deleter via Unsanitized theme ParameterEPSS 0.3%CVE-2026-54336MEDIUMJumpServer: KoKo Web Terminal SFTP Path Traversal on Authorized AssetEPSS 0.3%CVE-2025-66206MEDIUMFrappe vulnerable to a path traversal allowing reading certain filesEPSS 0.3%CVE-2025-61647LOWUserInfoCard: Don't allow access to information about users who are suppressed if you don't have suppressor rightsEPSS 0.3%CVE-2023-46122LOWArbitrary file write via archive extraction (Zip Slip) vulnerability in sbtEPSS 0.3%CVE-2026-77258HIGHMCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path()EPSS 0.3%