Fallos del tipo CWE-22

6046 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-84541MEDIUMAn input validation issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macEPSS 0.2%CVE-2026-86910MEDIUMA permissions issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS TahoEPSS 0.2%CVE-2026-50207HIGHLocal Modem Manipulation via Binder InterfacesEPSS 0.2%CVE-2026-62383MEDIUMnltk IPIPANCorpusReader Symlink Arbitrary File ReadEPSS 0.2%CVE-2026-29050MEDIUMmelange has Path Traversal When Resolving External Pipelines via Unvalidated pipeline[].usesEPSS 0.2%CVE-2026-13103HIGHA potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow aEPSS 0.2%CVE-2026-78249MEDIUMA path traversal vulnerability exists in the web management interface of multiple Multifunction Devices and Printers, including Apeos C4571 EPSS 0.2%CVE-2026-60088MEDIUMPraisonAI before 4.6.78 Path Traversal via Custom CommandsEPSS 0.2%CVE-2026-84534MEDIUMA path handling issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS GEPSS 0.2%CVE-2024-20805LOWPath traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.2EPSS 0.2%CVE-2026-21991MEDIUMA DTrace component, dtprobed, allows arbitrary file creation through crafted USDT provider names.EPSS 0.2%CVE-2026-55569MEDIUMaqua: Archive extraction in aqua follows attacker-planted symlinks, allowing writes outside the install directoryEPSS 0.2%CVE-2026-64756MEDIUMA path handling issue was addressed with improved validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS SequoEPSS 0.2%CVE-2026-84624MEDIUMA permissions issue was addressed with improved path validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOEPSS 0.2%CVE-2026-55846MEDIUMAllure: Path Traversal in Allure Report HTTP Server Allows Arbitrary File ReadEPSS 0.2%CVE-2026-32061MEDIUMOpenClaw < 2026.2.17 - Arbitrary File Read via $include Directive Path TraversalEPSS 0.2%CVE-2026-28457MEDIUMOpenClaw < 2026.2.14 - Path Traversal in Sandbox Skill Mirroring via Name ParameterEPSS 0.2%CVE-2026-95667MEDIUMMISP Installer Log and FIFO Created World-Readable, Exposing Sensitive CredentialsEPSS 0.2%CVE-2026-60089MEDIUMPraisonAI before 1.6.78 Path Traversal via config.tomlEPSS 0.2%CVE-2026-5656HIGHImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in WiresharkEPSS 0.2%