Fallos del tipo CWE-22

6040 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-76737LOWAuthenticated Local Path Traversal Vulnerability Leads to Denial-of-Service in HPE Networking Instant OnEPSS 0.1%CVE-2023-35670HIGHIn computeValuesFromData of FileUtils.java, there is a possible way to insert files to other apps' external private directories due to a patEPSS 0.1%CVE-2023-21093HIGHIn extractRelativePath of FileUtils.java, there is a possible way to access files in a directory belonging to other applications due to a paEPSS 0.1%CVE-2025-48550MEDIUMIn testGrantSlicePermission of SliceManagerTest.java, there is a possible permanent denial of service due to a path traversal error. This coEPSS 0.1%CVE-2024-47027HIGHIn sm_mem_compat_get_vmm_obj of lib/sm/shared_mem.c, there is a possible arbitrary physical memory access due to improper input validation. EPSS 0.1%CVE-2025-48636HIGHIn openFile of BugreportContentProvider.java, there is a possible way to read and write unauthorized files due to a path traversal error. ThEPSS 0.1%CVE-2026-102252MEDIUMPath Traversal in VMDK Extractor in OSV-SCALIBREPSS 0.1%CVE-2025-9142HIGHLocal privilege escalation in Harmony SASE Windows AgentEPSS 0.1%CVE-2026-106559MEDIUMBackstage: Improper input validation in Confluence to Markdown scaffolder moduleEPSS —CVE-2026-5049MEDIUMA path traversal vulnerability affects the The Zone Alias Import flow feature in Brocade SANnav before 3.0.0a. A local authenticated attackeEPSS —CVE-2026-102257HIGHA Zip Slip vulnerability in the in the SMA1000 Appliance Management Console (AMC) interface allows an attacker to extract files outside the EPSS —CVE-2026-101886MEDIUMCisco Jabber for Android Path Traversal via Shared Content URIEPSS —CVE-2026-106557HIGHBackstage: Improper input validation in TechDocs Markdown extension configurationEPSS —CVE-2026-103435HIGHArbitrary File Write via Write-Time Symlink Following (TOCTOU) in Claude CodeEPSS —CVE-2026-105816HIGHVault Vulnerable to Arbitrary Code Execution via Plugin Catalog Entries Restored From Raft SnapshotsEPSS —CVE-2026-42532MEDIUMA path traversal vulnerability exists in the EmailSheet extract_parts functionality of VisiData (version(s): dev (commit 38b21f78)). A speciEPSS —CVE-2026-94580MEDIUMAn arbitrary file and directory deletion vulnerability exists in the REST API management interface handling USB storage operations on BrocadEPSS —CVE-2026-41958MEDIUMA path traversal vulnerability exists in the unzip_http RemoteZipFile extract functionality of VisiData (version(s): dev (commit 38b21f78)).EPSS —CVE-2026-105820MEDIUMVault ACL Policy Cache Vulnerable to Cross-Namespace Policy ResolutionEPSS —CVE-2026-106560HIGHBackstage: Improper repository path validation in a Scaffolder backend moduleEPSS —