Fallos del tipo CWE-22

6050 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2025-11020HIGHRemote Code Execution in MarkAny SafePC EnterpriseEPSS 0.3%CVE-2026-48442HIGHCAI Content Credentials | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)EPSS 0.3%CVE-2025-63365HIGHSoftSea EPUB File Reader 1.0.0.0 is vulnerable to Directory Traversal. The vulnerability resides in the EPUB file processing component, specEPSS 0.3%CVE-2026-71313MEDIUMrclone: Local Encoding Path TraversalEPSS 0.3%CVE-2020-36970MEDIUMPMB 5.6 - 'chemin' Local File DisclosureEPSS 0.3%CVE-2026-86136HIGHFireware OS Missing Authorization in wgagent Management API Allows Denial of Service - Variant AEPSS 0.3%CVE-2024-47263MEDIUMAn improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository webapi component in SynEPSS 0.3%CVE-2026-60062MEDIUMNGINX Agent VulnerabilityEPSS 0.3%CVE-2018-10501—This vulnerability allows local attackers to escalate privileges on vulnerable installations of Samsung Notes Fixed in version 2.0.02.31. AnEPSS 0.3%CVE-2026-47862MEDIUMZipTransformer uses file_name header to build workDirectory path without sanitizationEPSS 0.3%CVE-2022-4772MEDIUMWidoco WidocoUtils.java unZipIt path traversalEPSS 0.3%CVE-2026-55825LOWContao: Possible path traversal in job download URIsEPSS 0.3%CVE-2026-25603MEDIUMPath Traversal vulnerability in Linksys MR9600, Linksys MX4200EPSS 0.3%CVE-2026-8662LOWPath Traversal in Rapid7 InsightConnect Compression PluginEPSS 0.3%CVE-2026-82915MEDIUMPath Traversal in Bimser Solution Software's eBA PlusEPSS 0.3%CVE-2026-88046MEDIUMrclone: source object names can escape the configured root on uploadEPSS 0.3%CVE-2026-48776MEDIUMLangGraph SDK has unsafe URL path constructionEPSS 0.3%CVE-2026-48446MEDIUMCAI Content Credentials | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)EPSS 0.3%CVE-2026-34664MEDIUMSubstance3D - Designer | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)EPSS 0.3%CVE-2026-17621MEDIUMLangflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base componentsEPSS 0.3%