Fallos del tipo CWE-22

6046 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2025-8054HIGHPath Traversal vulnerability have been discovered in OpenText™ XM Fax.EPSS 0.3%CVE-2026-15801HIGHCri-o: cri-o: insufficient validation during container checkpoint restoreEPSS 0.3%CVE-2026-32709MEDIUMPX4 Autopilot MAVLink FTP Unauthenticated Path Traversal (Arbitrary File Read/Write/Delete)EPSS 0.3%CVE-2025-54292MEDIUMClient-Side Path Traversal in LXD-UIEPSS 0.3%CVE-2026-7869MEDIUMLangflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcementEPSS 0.3%CVE-2024-6971LOWPath Traversal in parisneo/lollms-webuiEPSS 0.3%CVE-2026-40923MEDIUMTekton Pipelines: VolumeMount path restriction bypass via missing filepath.Clean in /tekton/ checkEPSS 0.3%CVE-2025-67720MEDIUMPyrofork has a Path Traversal in download_media MethodEPSS 0.3%CVE-2021-29088HIGHImproper limitation of a pathname to a restricted directory ('Path Traversal') in cgi component in Synology DiskStation Manager (DSM) beforeEPSS 0.3%CVE-2022-36035HIGHFlux CLI Workload InjectionEPSS 0.3%CVE-2018-25194HIGHNominas 0.27 SQL Injection via username ParameterEPSS 0.3%CVE-2026-82035HIGHPyMuPDF 1.28.2 Path Traversal via extract_objects() Font BranchEPSS 0.3%CVE-2017-20102MEDIUMAlbum Lock getImage path traversalEPSS 0.3%CVE-2026-51568HIGHmodelscope Agentscope v1.0.18-v1.0.0 is vulnerable to Path Traversal in write_text_file.EPSS 0.3%CVE-2026-77825MEDIUMIBM ContextForge MCP Gateway is affected by path traversalEPSS 0.3%CVE-2026-94238MEDIUMLoco Translate < 2.8.9 - Translator+ Limited File Read via 'path' ParameterEPSS 0.3%CVE-2025-61641LOWAPI list=allpages with maxsize is making really slow queriesEPSS 0.3%CVE-2026-90959HIGHPulpcore: pulpcore: file:// scheme allowlist bypass in content upload file_url field enables arbitrary file read and pulp container registry signing key theftEPSS 0.3%CVE-2026-2500MEDIUMQuick Playground <= 1.3.4 - Authenticated (Administrator+) Arbitrary File Read via 'filename' ParameterEPSS 0.3%CVE-2026-51862CRITICALDB-GPT 0.8.0 contains directory traversal in skill_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:40). A remoteEPSS 0.3%