Falhas do tipo CWE-22

5.970 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2026-73496HIGHMCP Atlassian: Arbitrary server-side file read via attachment uploadEPSS 0.5%CVE-2026-88938HIGHknowns through 0.33.0 Path Traversal via code.find MCP toolEPSS 0.5%CVE-2026-78599MEDIUMStored Path Traversal in Kibana Leading to Unauthorized Deletion of Internal ResourcesEPSS 0.5%CVE-2026-45775MEDIUMDiscourse: Cross-site backup access via path traversal in multisite local backupsEPSS 0.5%CVE-2026-63006MEDIUMZammad: HTML sanitizer API path allowlist bypass via interior path traversal in img src/srcsetEPSS 0.5%CVE-2025-66302MEDIUMGrav vulnerable to Path Traversal allowing server files backupEPSS 0.5%CVE-2026-24147MEDIUMNVIDIA Triton Inference Server contains a vulnerability in triton server where an attacker may cause an information disclosure by uploading EPSS 0.5%CVE-2026-13723MEDIUMDevelar's electron-builder allows arbitrary file overwriteEPSS 0.5%CVE-2026-43732MEDIUMA path handling issue was addressed with improved validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS TahoEPSS 0.5%CVE-2025-12382HIGHPath Traversal Allows Remote Code Execution in AlgoSec Firewall AnalyzerEPSS 0.5%CVE-2026-27884MEDIUMNetExec vulnerable to arbitrary file write via path traversal in spider_plus moduleEPSS 0.5%CVE-2025-14914HIGHIBM WebSphere Application Server Liberty Path TraversalEPSS 0.5%CVE-2026-31886CRITICALDagu has a Path Traversal via `dagRunId` in Inline DAG ExecutionEPSS 0.5%CVE-2026-64826HIGHrConfig < 8.2.13 Path Traversal File Read via FileDownloadControllerEPSS 0.5%CVE-2024-32111MEDIUMWordPress core < 6.5.5 - Auth. Arbitrary .html File Read (Windows Only) vulnerabilityEPSS 0.5%CVE-2026-14783MEDIUMNousResearch hermes-agent skills_tool.py skill_view path traversalEPSS 0.5%CVE-2026-79306MEDIUMCyberPanel v1.9.1 contains a path traversal vulnerability in the compress method exposed through the /filemanager/controller endpoint. An auEPSS 0.5%CVE-2024-45312MEDIUMArbitrary language parameter can passed to `aspell` executable via spelling requests in overleafEPSS 0.5%CVE-2026-11414CRITICALUnauthenticated File Exfiltration in Altium Enterprise Server Vault Service via Hard-coded Cryptographic Key and Path TraversalEPSS 0.5%CVE-2024-8685MEDIUMPath-Traversal vulnerability in Revolution PiEPSS 0.5%