Falhas do tipo CWE-22

5.969 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2026-49133HIGHTypemill < 2.24.0 Path Traversal via ControllerApiImage::getPagemedia()EPSS 0.5%CVE-2026-28078MEDIUMWordPress uListing plugin <= 2.2.0 - Arbitrary File Download vulnerabilityEPSS 0.5%CVE-2026-79773MEDIUMWinter CMS before 1.2.13 Local File Inclusion via JavaScriptEPSS 0.5%CVE-2024-25123HIGHPath Manipulation in file mslib/index.py in MSSEPSS 0.5%CVE-2025-43537LOWA path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2.EPSS 0.5%CVE-2025-25800MEDIUMSeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe_file.php.EPSS 0.5%CVE-2026-56394HIGHCraft CMS - Authenticated Path Traversal in assets/icon Extension ParameterEPSS 0.5%CVE-2026-73225HIGHelecterm: Path traversal in FTP/SFTP recursive folder download via unsanitized server filenameEPSS 0.5%CVE-2025-7975HIGHAnritsu ShockLine CHX File Parsing Directory Traversal Remote Code Execution VulnerabilityEPSS 0.5%CVE-2025-7359HIGHCounter live visitors for WooCommerce <= 1.3.6 - Unauthenticated Arbitrary File Deletion in wcvisitor_get_blockEPSS 0.5%CVE-2026-52868HIGHOFFIS DCMTK Toolkit Path TraversalEPSS 0.5%CVE-2026-72903HIGHTabby: Windows SFTP path traversal allows a malicious server to write files outside the selected download directoryEPSS 0.5%CVE-2026-73223HIGHelecterm: Path traversal in editWithSystemEditor temp file path via unsanitized SFTP filenameEPSS 0.5%CVE-2026-73227HIGHelecterm's RDP clipboard file download may parse unsafe file nameEPSS 0.5%CVE-2026-54591HIGHAsyncSSH: SCP Path Traversal to Arbitrary File WriteEPSS 0.5%CVE-2026-33529LOWZoraxy: Authenticated Path Traversal in Config Import leads to RCEEPSS 0.5%CVE-2026-54520HIGHAI Agent Automation: Workflow file step path traversal allows read and write outside the expected directoryEPSS 0.5%CVE-2026-41491HIGHDapr: Service Invocation path traversal ACL bypassEPSS 0.5%CVE-2026-32055HIGHOpenClaw < 2026.2.26 - Workspace Path Boundary Bypass via Non-existent SymlinkEPSS 0.5%CVE-2022-23970HIGHASUS RT-AX56U - Path TraversalEPSS 0.5%