Fallos del tipo CWE-22

6048 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-0270MEDIUMCortex XSOAR: Path Traversal VulnerabilityEPSS 0.2%CVE-2025-14698MEDIUMatlaszz AI Photo Team Galleryit App gallery.photogallery.pictures.vault.album path traversalEPSS 0.2%CVE-2026-35206MEDIUMHelm Chart extraction output directory collapse via `Chart.yaml` name dot-segmentEPSS 0.2%CVE-2025-14702MEDIUMSmartbit CommV Smartschool App be.smartschool.mobile.SplashActivity path traversalEPSS 0.2%CVE-2025-14699MEDIUMMunicorn FAX App biz.faxapp.app path traversalEPSS 0.2%CVE-2026-35338HIGHuutils coreutils chmod Path Traversal Bypass of --preserve-rootEPSS 0.2%CVE-2026-40027HIGHALEAPP NQ Vault Artifact Parser Path TraversalEPSS 0.2%CVE-2026-59152MEDIUMArbitrary server-side file read in LangSmith SDK TracingMiddlewareEPSS 0.2%CVE-2025-54160HIGHImproper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology BeeDrive for desktop beEPSS 0.2%CVE-2026-44192MEDIUMAnsible-lightspeed: ansible lightspeed mcp server: remote code execution and data exfiltration via path traversalEPSS 0.2%CVE-2023-21448MEDIUMPath traversal vulnerability in Samsung Cloud prior to version 5.3.0.32 allows attacker to access specific png file.EPSS 0.2%CVE-2026-54545HIGH@wakaru/cli arbitrary file write during bundle unpackEPSS 0.2%CVE-2026-35254MEDIUMVulnerability in the Oracle OCI CLI product of Oracle Open Source Projects. The supported versions that is affected is 3.77. Easily exploitaEPSS 0.2%CVE-2026-47764HIGHpdm: Path traversal in wheel installation via overridden write_to_fsEPSS 0.2%CVE-2026-35204HIGHHelm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directoryEPSS 0.2%CVE-2026-72783MEDIUMCraft CMS 5.0.0-RC1 before 5.10.6 Path Traversal via ensurePathIsContainedEPSS 0.2%CVE-2026-66484MEDIUMPath Traversal in GNU cpioEPSS 0.2%CVE-2022-41670HIGHA CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in the SGIUtility component thEPSS 0.2%CVE-2026-47243CRITICALKata guest escape: runtime-rs guest-root to host-root escape via virtiofsEPSS 0.2%CVE-2024-47566MEDIUMA improper limitation of a pathname to a restricted directory ('path traversal') [CWE-23] in Fortinet FortiRecorder version 7.2.0 through 7.EPSS 0.2%