Fallos del tipo CWE-22

6055 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-8770MEDIUMcontinuedev continue JSON-RPC Server lsTool.ts lsTool path traversalEPSS 0.2%CVE-2024-0129MEDIUMNVIDIA NeMo contains a vulnerability in SaveRestoreConnector where a user may cause a path traversal issue via an unsafe .tar file extractioEPSS 0.2%CVE-2026-51852HIGHagent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.save_file_b64. The savEPSS 0.2%CVE-2026-54319MEDIUMDaytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escapeEPSS 0.2%CVE-2022-36831MEDIUMPath traversal vulnerability in UriFileUtils of Samsung Notes prior to version 4.3.14.39 allows attacker to access some file as Samsung NoteEPSS 0.2%CVE-2022-29094HIGHDell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versionEPSS 0.2%CVE-2022-29093HIGHDell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versionEPSS 0.2%CVE-2026-78394MEDIUMLink Library < 7.9.6 - Contributor+ Path Traversal via 'filepath' ParameterEPSS 0.2%CVE-2026-101885HIGHZeroClaw before 0.8.5 Path Traversal via Plugin Manifest wasm_pathEPSS 0.2%CVE-2026-79809HIGHUnauthenticated Path Traversal in ClearPass Policy Manager API Endpoint Leads to Authorization BypassEPSS 0.2%CVE-2024-31965MEDIUMA vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 ConferenEPSS 0.2%CVE-2024-36508MEDIUMAn improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.EPSS 0.2%CVE-2024-31552HIGHCuteHttpFileServer v.3.1 version has an arbitrary file download vulnerability, which allows attackers to download arbitrary files on the serEPSS 0.2%CVE-2026-55557HIGHbrowse-mcp: Arbitrary file write via unconfined download and state pathsEPSS 0.2%CVE-2023-40439LOWA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.6 and iPadOS 16.6, macOS VEPSS 0.2%CVE-2023-25508MEDIUMNVIDIA DGX-1 BMC contains a vulnerability in the IPMI handler, where an attacker with the appropriate level of authorization can upload and EPSS 0.2%CVE-2026-18114MEDIUMIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS 0.2%CVE-2026-73234HIGHFreeCAD: FCStd path traversal allows arbitrary file write via unsanitized file attribute in PropertyFileIncluded::Restore()EPSS 0.2%CVE-2023-6407MEDIUM A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary fiEPSS 0.2%CVE-2025-0750MEDIUMCri-o: cri-o path traversal in log handling functions allows arbitrary unmountingEPSS 0.2%