Fallos del tipo CWE-22

6045 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-43723HIGHA path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.EPSS 0.2%CVE-2026-39973HIGHApktool: Path Traversal to Arbitrary File WriteEPSS 0.2%CVE-2026-13748MEDIUMSnowflake CLI Arbitrary Local File Read and Exfiltration Through Improper File Path RestrictionEPSS 0.2%CVE-2026-58203MEDIUMNestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_sizeEPSS 0.2%CVE-2022-36400MEDIUMPath traversal in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow anEPSS 0.2%CVE-2023-20943HIGHIn clearApplicationUserData of ActivityManagerService.java, there is a possible way to remove system files due to a path traversal error. ThEPSS 0.2%CVE-2026-50181HIGHLangroid: Path traversal in the file tools allows read/write outside configured current directoryEPSS 0.2%CVE-2026-44517MEDIUMBuildah: Build breakout using malicious Containerfile and Git Smart HTTP server or GitHub release tar archiveEPSS 0.2%CVE-2026-85456MEDIUMMOOS-IvP through 24.8.1 alog Splitting Path Traversal on WindowsEPSS 0.2%CVE-2026-47144MEDIUMShamefile has an arbitrary file read via shamefile.yaml in shame nextEPSS 0.2%CVE-2026-18953MEDIUMImproper limitation of a pathname to a restricted directory in aws-transform-mcp-serverEPSS 0.2%CVE-2026-53925HIGHGlances: Arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configurationEPSS 0.2%CVE-2026-86902MEDIUMA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27,EPSS 0.2%CVE-2026-22927HIGHOmnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability.EPSS 0.2%CVE-2026-86910MEDIUMA permissions issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS TahoEPSS 0.2%CVE-2026-29051MEDIUMmelange has Path Traversal via .PKGINFO in --persist-lint-resultsEPSS 0.2%CVE-2026-52872HIGHStreambert: Local File Exfiltration and Overwrite via Subtitle file: ProtocolEPSS 0.2%CVE-2026-62383MEDIUMnltk IPIPANCorpusReader Symlink Arbitrary File ReadEPSS 0.2%CVE-2026-50207HIGHLocal Modem Manipulation via Binder InterfacesEPSS 0.2%CVE-2026-77091HIGHDataCube Security Feature BypassEPSS 0.2%