Falhas do tipo CWE-22

5.970 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2026-23633MEDIUMGogs has arbitrary file read/write via path traversal in Git hook editingEPSS 0.5%CVE-2025-32209MEDIUMWordPress Total processing card payments for WooCommerce Plugin <= 7.1.5 - Arbitrary File Download vulnerabilityEPSS 0.5%CVE-2024-54169MEDIUMIBM EntireX path traversalEPSS 0.5%CVE-2026-65695HIGHOffice-Word-MCP-Server 1.1.11 Path Traversal via document toolsEPSS 0.5%CVE-2024-2210MEDIUMThe Plus Addons for Elementor <= 5.4.1 - Authenticated (Contributor+) Local File Inclusion via Team Member ListingEPSS 0.5%CVE-2025-10283CRITICALImproper .git Sanitization in gitdumper Enables RCEEPSS 0.5%CVE-2026-59149MEDIUMMockoon: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)EPSS 0.5%CVE-2026-59221HIGHopen-webui terminal proxy path traversal guard bypass via 9x encoded traversalEPSS 0.5%CVE-2024-47351HIGHWordPress MaxSlider plugin <= 1.2.3 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2026-27442CRITICALzip_attachments Path TraversalEPSS 0.5%CVE-2023-41888MEDIUMPhishing through a login page malicious URL in GLPIEPSS 0.5%CVE-2018-25144HIGHMicrohard Systems IPn4G 1.1.0 Arbitrary File Access via Undocumented System EditorEPSS 0.5%CVE-2026-73496HIGHMCP Atlassian: Arbitrary server-side file read via attachment uploadEPSS 0.5%CVE-2024-45074MEDIUMIBM webMethods Integration directory traversalEPSS 0.5%CVE-2026-44594HIGHesm.sh: Path Traversal via package.json browser field allows reading arbitrary server filesEPSS 0.5%CVE-2026-11944MEDIUMopenSIS Classic 9.3 - Authenticated path traversal in SentMail attachment downloadEPSS 0.5%CVE-2026-88938HIGHknowns through 0.33.0 Path Traversal via code.find MCP toolEPSS 0.5%CVE-2026-81030HIGHMage AI through 0.9.79 Arbitrary File Read via Unvalidated Path in browser_items EndpointEPSS 0.5%CVE-2026-85618HIGHConvertX 0.17.0 Arbitrary File Read via LaTeX Input DirectivesEPSS 0.5%CVE-2024-49771MEDIUMMPXJ has a Potential Path Traversal VulnerabilityEPSS 0.5%