Falhas do tipo CWE-22

5.970 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2026-39307HIGHPraisonAI has an Arbitrary File Write (Zip Slip) in Templates ExtractionEPSS 0.5%CVE-2026-18899HIGHLangflow is affected by multiple authentication bypass, path traversal, authorization, and server-side request forgery vulnerabilitiesEPSS 0.5%CVE-2026-41887MEDIUMFlarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)EPSS 0.5%CVE-2025-51463HIGHPath Traversal in restore_run_backup() in AIM 3.28.0 allows remote attackers to write arbitrary files to the server's filesystem via a craftEPSS 0.5%CVE-2025-3547MEDIUMfrdel Agent-Zero get_work_dir_files path traversalEPSS 0.5%CVE-2026-59924MEDIUMMistune: Arbitrary File Read via Include directive path traversalEPSS 0.5%CVE-2026-32808HIGHpyLoad: Arbitrary File Deletion via Path Traversal during Encrypted 7z Password VerificationEPSS 0.5%CVE-2025-14753HIGHIBM Cloud Pak for Data is vulnerable to path traversalEPSS 0.5%CVE-2024-35081HIGHLuckyFrameWeb v3.5.2 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter in the fileDownload methoEPSS 0.5%CVE-2025-53358MEDIUMkotaemon Vulnerable to Path Traversal via Link UploadEPSS 0.5%CVE-2023-54403HIGHYonyou U8 CRM Arbitrary File Read via getemaildata.phpEPSS 0.5%CVE-2026-5203MEDIUMCMS Made Simple UserGuide Module XML Import class.UserGuideImporterExporter.php _copyFilesToFolder path traversalEPSS 0.5%CVE-2026-44566HIGHOpen WebUI: Arbitrary File Upload and Path TraversalEPSS 0.5%CVE-2026-15700MEDIUMDedeCMS Album Publishing Feature zip.class.php ExtractFile path traversalEPSS 0.5%CVE-2026-6957HIGHPath traversal in Mattermost Legal Hold plugin via unsanitized file name from federated peer allows arbitrary file write.EPSS 0.5%CVE-2026-23888MEDIUMpnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip)EPSS 0.5%CVE-2026-34603HIGH@tinacms/graphql's Media Endpoints Can Escape the Media Root via Symlinks or JunctionsEPSS 0.5%CVE-2025-11016MEDIUMkalcaddle kodbox index.class.php fileOut path traversalEPSS 0.5%CVE-2023-41290MEDIUMQuFirewallEPSS 0.5%CVE-2026-54910HIGHFileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary filesEPSS 0.5%