Fallos del tipo CWE-22

6046 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2025-24889MEDIUMPath traversal in sd-log Qubes virtual machineEPSS 0.2%CVE-2024-45401HIGHstripe-cli Path Traversal vulnerabilityEPSS 0.2%CVE-2024-32944LOWPath traversal vulnerability exists in UTAU versions prior to v0.4.19. If a user of the product installs a crafted UTAU voicebank installer EPSS 0.2%CVE-2026-79904MEDIUMPhotoshop Mobile | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)EPSS 0.2%CVE-2026-79534MEDIUMmark3labs mcp-filesystem-server v0.11.1 is vulnerable to Directory Traversal due to an improper link resolution in validatePath (filesystemsEPSS 0.2%CVE-2026-65712MEDIUMJoomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extensionEPSS 0.2%CVE-2025-43465LOWA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Tahoe 26.1. An EPSS 0.2%CVE-2026-58302HIGHrtapi_app in linuxcnc-uspace in LinuxCNC before 2.9.9 allows privilege escalation. It is installed SUID root and loads shared library moduleEPSS 0.2%CVE-2026-55832MEDIUMTract: Arbitrary file read via unsanitized ONNX external_data `location` (path traversal) on model load in tract-onnxEPSS 0.2%CVE-2026-19589HIGHPacker vulnerable to arbitrary file write via crafted plugin archive during installationEPSS 0.2%CVE-2026-84568HIGHA path traversal issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS TEPSS 0.2%CVE-2026-25145MEDIUMmelange has a path traversal in license-path which allows reading files outside workspaceEPSS 0.2%CVE-2026-54093MEDIUMFile Browser: Path traversal in download-as-zip/tar via Windows-style backslash separators in stored filenamesEPSS 0.2%CVE-2026-42866MEDIUMTookie: Arbitrary file write via path traversal in -u username / -U userfile output filenameEPSS 0.2%CVE-2022-34855MEDIUMPath traversal for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalatiEPSS 0.2%CVE-2026-28816MEDIUMA path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe EPSS 0.2%CVE-2026-55878HIGHSymfony: Path Traversal in symfony/ux-toolkit Allows Arbitrary File Write and Read via Crafted Recipe ManifestEPSS 0.2%CVE-2026-49836MEDIUMpsd-tools: arbitrary file write via smart-object filenameEPSS 0.2%CVE-2026-32685MEDIUMPath Traversal in gleam docs build via documentation.pages Allows Arbitrary File Read and WriteEPSS 0.2%CVE-2020-26071HIGHCisco SD-WAN vEdge Arbitrary File Creation VulnerabilityEPSS 0.2%