Falhas do tipo CWE-22

5.927 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2026-47659HIGHPathling has path traversal in $import-pnp manifest that enables read-capable SSRF via /jobs/{jobId}/{filename}EPSS 0.6%CVE-2026-12942HIGHLangflow is affected by path traversal due to multiple unauthenticated and insufficiently authorized API endpointsEPSS 0.6%CVE-2026-55488HIGHmotionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File ReadEPSS 0.6%CVE-2026-47661HIGHPathling has path traversal in $result endpoint that allows arbitrary warehouse file readEPSS 0.6%CVE-2026-3366HIGHInfoSphere Optim Test Data Fabrication is affected by Arbitrary File ReadEPSS 0.6%CVE-2026-14519HIGHIBM App Connect Enterprise is vulnerable to an arbitrary file read and arbitrary changes to configuration settingsEPSS 0.6%CVE-2024-34193HIGHsmanga 3.2.7 does not filter the file parameter at the PHP/get file flow.php interface, resulting in a path traversal vulnerability that canEPSS 0.6%CVE-2024-30509MEDIUMWordPress SellKit plugin <= 1.8.1 - Arbitrary File Download vulnerabilityEPSS 0.6%CVE-2026-87983CRITICALAn arbitrary file read vulnerability in Mistral Vibe, introduced in version 2.6.0, allows an attacker to bypass workspace restrictions usingEPSS 0.6%CVE-2026-17473HIGHIBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code executionEPSS 0.6%CVE-2024-37499MEDIUMWordPress Online Booking & Scheduling Calendar for WordPress plugin <= 4.4.2 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2025-52861HIGHVioStorEPSS 0.6%CVE-2019-25610HIGHNetNumber Titan Master 7.9.1 Path Traversal via drpEPSS 0.6%CVE-2022-39178MEDIUMWebvendome - webvendome Internal Server IP DisclosureEPSS 0.6%CVE-2026-65600HIGHTraefik before v2.11.52 Authentication Bypass via ReplacePathRegexEPSS 0.6%CVE-2025-30878HIGHWordPress JS Help Desk plugin <= 2.9.2 - Arbitrary File Deletion vulnerabilityEPSS 0.6%CVE-2026-7400MEDIUMgeekgod382 filesystem-mcp-server read_file_tool/write_file_tool server.py is_path_allowed path traversalEPSS 0.6%CVE-2026-7237MEDIUMAgiFlow scaffold-mcp write-to-file Tool index.ts path traversalEPSS 0.6%CVE-2024-37454MEDIUMWordPress AWSM Team – Team Showcase Plugin plugin <= 1.3.1 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2026-7386MEDIUMfatbobman mail-mcp-bridge mail_mcp_server.py path traversalEPSS 0.6%