Fallos del tipo CWE-22

5865 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-89040CRITICALTencent Mass Service Engine in Cluster (MSEC) path traversalEPSS 1.1%CVE-2021-29091HIGHImproper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file management component in Synology Photo EPSS 1.1%CVE-2026-100372HIGHClipBucket v5 before 5.5.3-#197 Path Traversal via template_editor.phpEPSS 1.1%CVE-2026-15601MEDIUMKirki <= 6.0.13 - Authenticated (Editor+) Path Traversal to Arbitrary File Write (Zip Slip)EPSS 1.1%CVE-2025-4564CRITICALTicketBAI Facturas para WooCommerce <= 3.18 - Unauthenticated Arbitrary File DeletionEPSS 1.1%CVE-2026-15457MEDIUMKirki <= 6.0.13 - Authenticated (Editor+) Path Traversal to Arbitrary Directory Deletion via 'family' ParameterEPSS 1.1%CVE-2025-6445HIGHServiceStack FindType Directory Traversal Remote Code Execution VulnerabilityEPSS 1.1%CVE-2019-12666MEDIUMCisco IOS XE Software Path Traversal VulnerabilityEPSS 1.1%CVE-2020-15141LOWPath Traversal in openapi-python-clientEPSS 1.1%CVE-2023-31861HIGHZLMediaKit 4.0 is vulnerable to Directory Traversal.EPSS 1.1%CVE-2025-3404HIGHDownload Manager <= 3.3.12 - Authenticated (Author+) Arbitrary File DeletionEPSS 1.1%CVE-2024-21542HIGHVersions of the package luigi before 3.6.0 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) due to improper destinatEPSS 1.1%CVE-2021-21001CRITICALWAGO: PFC200 Access to files outside the home directoryEPSS 1.1%CVE-2021-22736—Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnEPSS 1.1%CVE-2025-6805HIGHMarvell QConvergeConsole deleteEventLogFile Directory Traversal Arbitrary File Deletion VulnerabilityEPSS 1.1%CVE-2022-35235MEDIUMWordPress WPide plugin <= 2.6 - Authenticated Arbitrary File Read vulnerabilityEPSS 1.1%CVE-2025-21623HIGHClipBucket V5 Unauthenticated Template Directory Update to Denial-of-ServiceEPSS 1.1%CVE-2022-45388HIGHJenkins Config Rotator Plugin 2.0.1 and earlier does not restrict a file name query parameter in an HTTP endpoint, allowing unauthenticated EPSS 1.1%CVE-2026-30869CRITICALSiYuan has a Path Traversal in /export Endpoint Allows Arbitrary File Read and Secret LeakageEPSS 1.1%CVE-2022-24718HIGHPath Traversal in ssr-pagesEPSS 1.1%