Fallos del tipo CWE-22

6045 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-24846MEDIUMmalcontent's archive extraction could write outside extraction directoryEPSS 0.2%CVE-2026-58413MEDIUMEnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment dataEPSS 0.2%CVE-2026-43749HIGHA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.8,EPSS 0.2%CVE-2026-58414MEDIUMNetwork-AI: EnvironmentManager.backup() follows symlinked directories and copies files outside the environment root into backupsEPSS 0.2%CVE-2026-58481MEDIUMNetwork-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directoryEPSS 0.2%CVE-2026-7875CRITICALNanoClaw Host/Container Filesystem Boundary Vulnerability via Outbound Attachment HandlingEPSS 0.2%CVE-2026-43772HIGHA path traversal issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOSEPSS 0.2%CVE-2026-43691HIGHA path handling issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 2EPSS 0.2%CVE-2026-29780MEDIUMeml_parser: Path Traversal in Official Example Script Leading to Arbitrary File WriteEPSS 0.2%CVE-2026-35570HIGHOpenClaude has Sandbox Bypass via Early-Exit Logic Flaw that Allows Path TraversalEPSS 0.2%CVE-2026-43989HIGHJunoClaw: upload_wasm accepted arbitrary filesystem paths without validationEPSS 0.2%CVE-2026-96419MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in WiresharkEPSS 0.2%CVE-2026-45224MEDIUMCrabbox < 0.9.0 Path Traversal via Islo Provider Workspace ResolutionEPSS 0.2%CVE-2026-30853MEDIUMcalibre has a Path Traversal Leading to Arbitrary File WriteEPSS 0.2%CVE-2026-84201MEDIUMappium-mcp-server through 0.1.61 Path Traversal in write_file and write_files_batchEPSS 0.2%CVE-2023-5097HIGHImproper Input Validation vulnerability in HYPR Workforce Access on Windows allows Path Traversal.This issue affects Workforce Access: beforEPSS 0.2%CVE-2026-69112MEDIUMHugging Face Accelerate 1.14.0 Path Traversal and DoS via weight_mapEPSS 0.2%CVE-2026-28482HIGHOpenClaw < 2026.2.12 - Path Traversal via Unsanitized sessionId and sessionFile ParametersEPSS 0.2%CVE-2026-39973HIGHApktool: Path Traversal to Arbitrary File WriteEPSS 0.2%CVE-2026-49497MEDIUMGhidra < 12.1 - Path Traversal via .gnu_debuglink in DWARF External Debug File ResolutionEPSS 0.2%