Fallos del tipo CWE-22

6055 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-32146HIGHImproper Path Validation in Git Dependency Handling Allows Arbitrary File System ModificationEPSS 0.2%CVE-2026-6855HIGHInstructlab: instructlab: path traversal allows arbitrary directory creation and file writeEPSS 0.2%CVE-2026-48105HIGHArc Enterprise cluster FSM applyRegisterFile accepts arbitrary file paths without validation, enabling cluster-wide path-traversal worm primitiveEPSS 0.2%CVE-2024-13894MEDIUMPath traversal in Smartwares camerasEPSS 0.2%CVE-2026-43940HIGHelecterm: Path traversal in electerm runWidget leads to arbitrary code executionEPSS 0.2%CVE-2025-9963CRITICALPath TraversalEPSS 0.2%CVE-2026-52752HIGHGhidra < 12.0.2 - Path Traversal in Extension Installer via ZIP Entry NamesEPSS 0.2%CVE-2026-52755HIGHGhidra < 12.0.4 - Path Traversal via Zip Slip in Theme ImportEPSS 0.2%CVE-2023-41780MEDIUMUnsafe DLL Loading Vulnerability in ZTE ZXCLOUD iRAIEPSS 0.2%CVE-2026-57171HIGHTrestle is vulnerable to arbitrary file write via path traversal in author generate commands (Incomplete fix of CVE-2026-46345)EPSS 0.2%CVE-2026-32711HIGHpydicom: Path traversal in FileSet/DICOMDIR ReferencedFileID allows file access outside the File-set rootEPSS 0.2%CVE-2026-94185MEDIUMnvm alias resolution follows `..` and discloses files outside $NVM_DIR/aliasEPSS 0.2%CVE-2022-42287MEDIUMNVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can upload and download arbitrary files under certain circEPSS 0.2%CVE-2025-43382MEDIUMA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.2,EPSS 0.2%CVE-2023-40383LOWA path handling issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.3. An app may be able to access user-sEPSS 0.2%CVE-2024-31587MEDIUMSecuSTATION Camera V2.5.5.3116-S50-SMA-B20160811A and lower allows an unauthenticated attacker to download device configuration files via a EPSS 0.2%CVE-2026-12171HIGHauto-changelog: code execution via untrusted in-repository configuration (handlebarsSetup/plugins), plus argument injection, path traversal, and SSRFEPSS 0.2%CVE-2026-71168HIGHDell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vuEPSS 0.2%CVE-2022-34429MEDIUMDell Hybrid Client below 1.8 version contains a Zip Slip Vulnerability in UI. A guest privilege attacker could potentially exploit this vulnEPSS 0.2%CVE-2025-59825MEDIUMastral-tokio-tar has a path traversal in tar extractionEPSS 0.2%