Fallos del tipo CWE-36

144 resultados

Travessia de diretório via caminho absoluto não validado

A aplicação recebe um caminho de arquivo do usuário e o coloca dentro de um diretório restrito, mas não valida se o caminho é absoluto (começando com /) ou contém sequências que escapam dessa restrição. Um atacante fornece um caminho como /etc/passwd e consegue acessar qualquer lugar do sistema de arquivos, não apenas o diretório pretendido.

Ejemplo

Uma API recebe ?arquivo=../../etc/passwd ou arquivo=/etc/shadow e tenta salvar em /uploads/arquivo, mas não neutraliza o caminho absoluto ou as sequências de escape. O arquivo é acessado fora da pasta segura. CVEs reais envolvem plataformas de compartilhamento de arquivos e serviços web que confiam na entrada do usuário sem sanitização.

Cómo mitigar

Valide e normalize todo caminho recebido: rejeite caminhos absolutos (com /), remova ../ e qualquer sequência de escape, e confirme que o caminho final fica dentro do diretório autorizado. Use funções seguras de manipulação de caminhos da linguagem (realpath, Path.resolve, etc.) e compare o resultado com o prefixo permitido.

CVE-2026-26337HIGHHyland Alfresco Transformation Service Absolute Path Traversal Arbitrary File Read and SSRFEPSS 0.4%CVE-2026-47243CRITICALKata guest escape: runtime-rs guest-root to host-root escape via virtiofsEPSS 0.4%CVE-2026-68896HIGHMicrosoft Windows Search Component Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-15236MEDIUMQuanta Computer|QOCA aim AI Medical Cloud Platform - Path TraversalEPSS 0.3%CVE-2025-15237MEDIUMQuanta Computer|QOCA aim AI Medical Cloud Platform - Path TraversalEPSS 0.3%CVE-2026-69612HIGHWindows Error Reporting Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2024-12643HIGHChunghwa Telecom tbm-client - Arbitrary File DeleteEPSS 0.3%CVE-2026-53698MEDIUMSilverpeas through 6.4.6 mishandles the "Personal space" feature that is selected when no componentId is set.EPSS 0.3%CVE-2024-12646HIGHChunghwa Telecom topm-client - Arbitrary File DeleteEPSS 0.3%CVE-2026-27117MEDIUMbit7z has a path traversal vulnerabilityEPSS 0.3%CVE-2026-54202HIGHTeamDavid: Path Traversal in the archive creation functionalityEPSS 0.3%CVE-2024-12644HIGHChunghwa Telecom tbm-client - Arbitrary File Copy and PasteEPSS 0.3%CVE-2026-13346MEDIUMpip absolute path traversal during download from malicious package indexesEPSS 0.3%CVE-2024-57966MEDIUMlibarchiveplugin.cpp in KDE ark before 24.12.0 can extract to an absolute path from an archive.EPSS 0.3%CVE-2025-13282HIGHChunghwa Telecom|TenderDocTransfer - Arbitrary File DeleteEPSS 0.3%CVE-2021-34711MEDIUMCisco IP Phone Software Arbitrary File Read VulnerabilityEPSS 0.3%CVE-2025-67898MEDIUMMJML through 4.18.0 allows mj-include directory traversal to test file existence and (in the type="css" case) read files. NOTE: this issue eEPSS 0.3%CVE-2025-13283HIGHChunghwa Telecom|TenderDocTransfer - Arbitrary File Copy and PasteEPSS 0.2%CVE-2023-40597HIGHAbsolute Path Traversal in Splunk Enterprise Using runshellscript.pyEPSS 0.2%CVE-2026-46345HIGHcompliance-trestle - jinja has an Arbitrary File Write via Path TraversalEPSS 0.2%