Fallos del tipo CWE-22

6049 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-106496LOWBackstage: Inconsistent enforcement of allowed location types during catalog processingEPSS 0.2%CVE-2026-73737MEDIUMUnauthenticated Path Traversal in HPE Networking Fabric Composer API Endpoint Allows Unauthorized File ModificationEPSS 0.2%CVE-2026-102262HIGHNewell Brands DYMO ID parent directory open to path traversal through improper spheres of controlEPSS 0.2%CVE-2026-18853MEDIUMZomboDroid Meme Generator App com.zombodroid.MemeGenerator t5.l.c path traversalEPSS 0.2%CVE-2026-8736LOWOinone Pamirs RestController LocalFileClient.java request.getParameter path traversalEPSS 0.2%CVE-2026-21822MEDIUMA path traversal vulnerability has been identified in HCL AppScan 360° (CVE-2026-21822).EPSS 0.2%CVE-2022-20850MEDIUMCisco SD-WAN Arbitrary File Deletion VulnerabilityEPSS 0.2%CVE-2026-84852MEDIUMReader Tools PDF Reader App File ActSplashNew.handleDeeplink path traversalEPSS 0.2%CVE-2026-84431MEDIUMAirAsia MOVE App com.airasia.mobile com.airasia.core.utils.RealPathUtil.getRealPath path traversalEPSS 0.2%CVE-2026-84442MEDIUMMapQuest Get Directions App com.mapquest.android.ace ExpoShareIntentModule.kt getDataColumn path traversalEPSS 0.2%CVE-2026-55443MEDIUMLangChain: Path traversal and sandbox escape in LangChain file-search middleware and loadersEPSS 0.2%CVE-2026-18648MEDIUMBlix Email Blue Mail Calendar App react-native-receive-sharing-intent FileDirectory.getFileFromUri path traversalEPSS 0.2%CVE-2026-64740CRITICALA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.10 and iPadOEPSS 0.2%CVE-2026-12565MEDIUMPath Traversal (Zip-Slip) in unarchive moduleEPSS 0.2%CVE-2026-44022MEDIUMDocling: Potential Path Traversal via LaTeX \includegraphics and \input CommandsEPSS 0.2%CVE-2026-40024HIGHSleuth Kit tsk_recover Path TraversalEPSS 0.2%CVE-2026-46555HIGHWhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary file exfiltrationEPSS 0.2%CVE-2026-45668CRITICALTrilium Notes : Note Import to RCE via #docName Path Traversal (Safe Import Enabled)EPSS 0.2%CVE-2025-53951MEDIUMAn Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiDLP Agent's OutlooEPSS 0.2%CVE-2026-24801MEDIUMA Potential SPA-vulnerability in Ralim/IronOSEPSS 0.2%