Falhas do tipo CWE-22

5.968 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2026-41589CRITICALWish has SCP Path Traversal that allows arbitrary file read/writeEPSS 0.5%CVE-2024-37501HIGHWordPress Advanced Classifieds & Directory Pro plugin <= 3.1.3 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2026-42574HIGHapko dirFS has a symlink-following path traversal that allows multiple entry points to escape the build rootEPSS 0.5%CVE-2024-25614MEDIUMThere is an arbitrary file deletion vulnerability in the CLI used by ArubaOS. Successful exploitation of this vulnerability results in the aEPSS 0.5%CVE-2026-40180HIGHZip Slip Path Traversal in quarkus-openapi-generator ApicurioCodegenWrapper classEPSS 0.5%CVE-2025-25155HIGHWordPress Music Sheet Viewer plugin <= 4.1 - Arbitrary File Read vulnerabilityEPSS 0.5%CVE-2023-3330—Improper Limitation of a Pathname to a Restricted Directory vulnerability in NEC Corporation Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2,EPSS 0.5%CVE-2024-35781MEDIUMWordPress Word Balloon plugin <= 4.21.1 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2026-93013MEDIUMRAGFlow through 0.27.2 Tenant Import Endpoints Path TraversalEPSS 0.5%CVE-2026-32026HIGHOpenClaw < 2026.2.24 - Arbitrary File Read via Improper Temporary Path Validation in SandboxEPSS 0.5%CVE-2026-15138MEDIUMtumf mcp-text-editor text_editor.py _validate_file_path path traversalEPSS 0.5%CVE-2025-49138MEDIUMHAX CMS vulnerable to Local File Inclusion via saveOutline API Location ParameterEPSS 0.5%CVE-2024-38704MEDIUMWordPress Team Manager plugin <= 2.1.12 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2026-32030HIGHOpenClaw < 2026.2.19 - Sensitive File Disclosure via stageSandboxMedia Path TraversalEPSS 0.5%CVE-2025-2032MEDIUMChestnutCMS rename renameFile path traversalEPSS 0.5%CVE-2026-59510HIGHAuthenticated Path Traversal in AIL Framework PDF Object Handling Enables Potential Arbitrary File ReadEPSS 0.5%CVE-2026-32567MEDIUMWordPress YML for Yandex Market plugin < 5.3.0 - Arbitrary File Deletion vulnerabilityEPSS 0.5%CVE-2026-39369HIGHWWBN AVideo's GIF poster fetch bypasses traversal scrubbing and exposes local files through public media URLsEPSS 0.5%CVE-2026-56138MEDIUMAuthenticated Path Traversal in AIL framework /objects/item/diff Allows Reading Gzip-Compressed FilesEPSS 0.5%CVE-2025-46486MEDIUMWordPress Nomupay Payment Processing Gateway plugin <= 7.1.7 - Arbitrary File Download VulnerabilityEPSS 0.5%