Fallos del tipo CWE-22

6045 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-22171HIGHOpenClaw < 2026.2.19 - Path Traversal in Feishu Media Temporary File NamingEPSS 0.3%CVE-2026-97226MEDIUMDbGate files-style Endpoint files.js fs.readFile path traversalEPSS 0.3%CVE-2026-2216MEDIUMrachelos WeRSS we-mp-rss tools.py download_export_file path traversalEPSS 0.3%CVE-2026-96678MEDIUMweiqingwen spring-boot-forum Avatar Upload NewUserFormValidator.java validate path traversalEPSS 0.3%CVE-2026-47121MEDIUMSparkle: Binary delta apply intermediate-symlink traversal in malicious .deltaEPSS 0.3%CVE-2024-47191HIGHpam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running EPSS 0.3%CVE-2026-97232MEDIUMvolotat Anagnorisis page.html start_streaming path traversalEPSS 0.3%CVE-2026-101142MEDIUMEleveo Quality Management Questionnaire Audio Upload Scorecard.jsp path traversalEPSS 0.3%CVE-2026-15921LOWnvm path traversal via a malicious mirror's LTS codename writes outside the alias directoryEPSS 0.3%CVE-2026-86087MEDIUMIBM® Db2® could allow an authenticated user to send a specially crafted request to write arbitrary files on the systemEPSS 0.3%CVE-2026-30915MEDIUMSFTPGo improperly sanitizes placeholders in group home directories/key prefixesEPSS 0.3%CVE-2026-0704MEDIUMIn affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field EPSS 0.3%CVE-2026-18465MEDIUMWP Maps Pro < 6.1.3 - Unauthenticated Local File InclusionEPSS 0.3%CVE-2025-30470MEDIUMA path handling issue was addressed with improved logic. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 1EPSS 0.3%CVE-2025-53080HIGHImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Samsung DMS(Data Management Server) allows authenticated aEPSS 0.3%CVE-2026-71426HIGHGetSimple CMS: Authenticated Stored Local File Inclusion (LFI) via page "template" fieldEPSS 0.3%CVE-2026-64777MEDIUMA malicious builder peer may be able to request an in-context file by name from the host and receive the contents of whatever the name resolEPSS 0.3%CVE-2026-34371MEDIUMLibreChat Affected by Arbitrary File Write via `execute_code` Artifact Filename TraversalEPSS 0.3%CVE-2026-14470MEDIUMLangflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base componentsEPSS 0.3%CVE-2026-23484MEDIUMBlinko: Authenticated Arbitrary File Write - saveDevPluginEPSS 0.3%