Fallos del tipo CWE-22

6046 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-63225MEDIUMRedocly CLI: Path traversal when using `split` commandEPSS 0.2%CVE-2026-9108MEDIUMStudio 5000 Logix Designer® – Multiple VulnerabilitiesEPSS 0.2%CVE-2026-47712LOWDulwich doesn't sanitize commit subjects in `porcelain.format_patch`EPSS 0.2%CVE-2026-73657MEDIUMTrigger.dev: Cross-tenant payload poisoning via packet write + replayEPSS 0.2%CVE-2025-3722NONEA path traversal vulnerability in System Information Reporter (SIR) 1.0.3 and prior allowed an authenticated high privileged user to issue EPSS 0.2%CVE-2026-49406MEDIUMDeno: BYONM module resolution allows `package.json` main path traversal to bypass `--allow-read` restrictionsEPSS 0.2%CVE-2026-19324MEDIUMHelloGGX shadcn-vue-mcp callback-server.ts fs.promises.readFile path traversalEPSS 0.2%CVE-2026-65382MEDIUMA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27,EPSS 0.2%CVE-2026-25636HIGHcalibre has a Path Traversal Leading to Arbitrary File Corruption and Code ExecutionEPSS 0.2%CVE-2026-54557MEDIUMmise HTTP backend uses raw version path for install symlink destinationEPSS 0.2%CVE-2026-19366MEDIUMNocteDefensor LudusMCP insert_creds_range_config insertCredsRangeConfig.ts path traversalEPSS 0.2%CVE-2026-15526MEDIUMaugmnt augments-mcp-server scan_project_deps scan-project-deps.ts scanProjectDeps path traversalEPSS 0.2%CVE-2026-104853MEDIUMNx: Path traversal in nx migrate package-migrations extractionEPSS 0.2%CVE-2026-19046MEDIUMNocteDefensor LudusMCP ludus_environment_guides_search ludusEnvironmentGuidesSearch.ts path traversalEPSS 0.2%CVE-2026-19368MEDIUMPV-Bhat gemsuite-mcp gemini_search unified-gemini.ts path traversalEPSS 0.2%CVE-2026-14985HIGHCVE-2026-14985EPSS 0.2%CVE-2026-15524MEDIUMalioshr memory-bank-mcp list-project-files-validation-factory.ts path traversalEPSS 0.2%CVE-2023-27409LOWA vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). A path traversal vulnerability was found in the `deviceinfo` EPSS 0.2%CVE-2026-67397HIGHPath traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root.EPSS 0.2%CVE-2026-88790LOWproma-ai Proma File Preview Service file-preview-service.ts resolveTargetPath path traversalEPSS 0.2%