Fallos del tipo CWE-22

6046 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-48072MEDIUMDocmost: Public image fileName path traversal leads to unauthorized local file readEPSS 0.3%CVE-2023-43801MEDIUMPath traversal in Arduino Create AgentEPSS 0.3%CVE-2026-90445HIGHPath Traversal in MalcolmEPSS 0.3%CVE-2023-43803MEDIUMPath traversal in Arduino Create AgentEPSS 0.3%CVE-2026-49850HIGHInvoicePlane: Missing CSRF Protection on State-Changing delete ActionsEPSS 0.3%CVE-2024-47267LOWImproper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull functionality in Synology SurEPSS 0.3%CVE-2026-6925MEDIUMMultiple Vulnerabilities in IBM Concert SoftwareEPSS 0.3%CVE-2026-84882HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.3%CVE-2026-106486HIGHBackstage: Improper filesystem validation in Bitbucket pull-request scaffolder actionsEPSS 0.3%CVE-2026-102332MEDIUMDozzle before 11.1.2 Path Traversal via Log ZIP DownloadEPSS 0.3%CVE-2026-61647HIGH@roomi-fields/notebooklm-mcp has path traversal in vault.batch tool that allows arbitrary file write outside intended vault directoryEPSS 0.3%CVE-2026-102123HIGHKiteworks Core Path TraversalEPSS 0.3%CVE-2023-52544MEDIUMVulnerability of file path verification being bypassed in the email module. Impact: Successful exploitation of this vulnerability may affectEPSS 0.3%CVE-2026-11467MEDIUMjishenghua jshERP addAccountHeadAndDetail Endpoint AccountHeadService.java path traversalEPSS 0.3%CVE-2024-12425LOWPath traversal leading to arbitrary .ttf file writeEPSS 0.3%CVE-2022-28543MEDIUMPath traversal vulnerability in Samsung Flow prior to version 4.8.07.4 allows local attackers to read arbitrary files as Samsung Flow permisEPSS 0.3%CVE-2026-47679HIGHGLPI: arbitrary file deletionEPSS 0.3%CVE-2026-59944MEDIUMComposer: CVE-2026-59946 fix bypass via symlinked package bin pathEPSS 0.3%CVE-2024-32163MEDIUMCMSeasy 7.7.7.9 is vulnerable to code execution.EPSS 0.3%CVE-2025-8054HIGHPath Traversal vulnerability have been discovered in OpenText™ XM Fax.EPSS 0.3%