Falhas do tipo CWE-22

5.908 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2026-81560MEDIUMblackms aistack Static File server.ts path traversalEPSS 0.7%CVE-2024-5852MEDIUMWordPress File Upload <= 4.24.7 - Authenticated (Contributor+) Directory TraversalEPSS 0.7%CVE-2025-12960MEDIUMSimple CSV Table <= 1.0.1 - Directory Traversal to Authenticated (Contributor+) Arbitrary File ReadEPSS 0.7%CVE-2026-36726MEDIUMAn arbitrary file deletion vulnerability in the /api/delete-temp-license/{file} endpoint of bookcars v8.3 allows unauthenticated attackers tEPSS 0.7%CVE-2022-3940LOWlanyulei ferry task.go path traversalEPSS 0.7%CVE-2024-51998HIGHPath traversal using file URI scheme without supplying hostname in changedetection.ioEPSS 0.7%CVE-2026-15990HIGHFormidable Charts <= 2.0.1 - Unauthenticated Arbitrary File Read via 'frm_graph' ParameterEPSS 0.7%CVE-2024-7744MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Progress WS_FTP ServerEPSS 0.7%CVE-2026-54670CRITICALWeGIA: Unauthenticated Auth Bypass + Local File InclusionEPSS 0.7%CVE-2026-101067MEDIUMdbgate save-uploaded-file Endpoint files.js saveUploadedFile path traversalEPSS 0.7%CVE-2026-101066MEDIUMdbgate Archive Link Creation archive.js createLink path traversalEPSS 0.7%CVE-2024-44195HIGHA logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.1. An app may be able to read arbitrary files.EPSS 0.7%CVE-2026-63490HIGHHandlebars.java: Arbitrary file read in `SpringTemplateLoader` via URL-fragment suffix bypassEPSS 0.7%CVE-2026-85661CRITICALexcel-mcp-server 0.1.8 Arbitrary File Read/Write via stdio modeEPSS 0.7%CVE-2026-55607HIGHClaude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code ExecutionEPSS 0.7%CVE-2024-51751MEDIUMArbitrary file read with File and UploadButton components in GradioEPSS 0.7%CVE-2026-50180HIGHLangroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file readEPSS 0.7%CVE-2026-53872HIGHpicklescan - Arbitrary File Read via Unsafe Pickle DeserializationEPSS 0.7%CVE-2024-37043MEDIUMQTS, QuTS heroEPSS 0.7%CVE-2024-37046LOWQTS, QuTS heroEPSS 0.7%