Falhas do tipo CWE-22

5.972 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2026-49238HIGHSFTP Server VM Escape in Canonical MultipassEPSS 0.4%CVE-2023-41291MEDIUMQuFirewallEPSS 0.4%CVE-2026-55156MEDIUMToken Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API EndpointsEPSS 0.4%CVE-2025-57712MEDIUMQsync CentralEPSS 0.4%CVE-2026-48129MEDIUMKestra task inputFiles accepts traversal filenames for worker file writesEPSS 0.4%CVE-2025-65838HIGHPublicCMS V5.202506.b is vulnerable to path traversal via the doUploadSitefile method.EPSS 0.4%CVE-2024-34808MEDIUMWordPress JCH Optimize plugin <= 4.2.0 - Path Traversal vulnerabilityEPSS 0.4%CVE-2026-28791HIGHPath Traversal in Media Upload Handle in TinaEPSS 0.4%CVE-2025-11182HIGHFile Download in GTONE ChangeFlowEPSS 0.4%CVE-2025-63372MEDIUMArticentgroup Zip Rar Extractor Tool 1.345.93.0 is vulnerable to Directory Traversal. The vulnerability resides in the ZIP file processing cEPSS 0.4%CVE-2026-60009HIGHIn Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled EPSS 0.4%CVE-2024-23774HIGHAn issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An unquoted Windows search path vulnerability exists in the KEPSS 0.4%CVE-2026-1703LOWLimited path traversal when installing wheel archivesEPSS 0.4%CVE-2026-40724MEDIUMWordPress Client Portal (Pro) plugin <= 5.6.2 - Arbitrary File Download vulnerabilityEPSS 0.4%CVE-2026-87030HIGHTanium addressed a path traversal vulnerability in Comply.EPSS 0.4%CVE-2026-65582HIGHWordPress AI Hub theme <= 1.3.10 - Arbitrary File Download vulnerabilityEPSS 0.4%CVE-2025-60242HIGHWordPress Download Counter plugin <= 1.4 - Arbitrary File Download vulnerabilityEPSS 0.4%CVE-2026-47277MEDIUMRuntipi: Unauthenticated arbitrary file read through app-store logo symlinksEPSS 0.4%CVE-2026-14194MEDIUMPath Traversal Allows Arbitrary File Download in Bilin Software's HUMANIST Digital Human ResourcesEPSS 0.4%CVE-2026-35605MEDIUMFile Browser has an access rule bypass via HasPrefix without trailing separator in path matchingEPSS 0.4%