Falhas do tipo CWE-22

5.979 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2024-40646HIGHVertex Vulnerable to Path TraversalEPSS 0.4%CVE-2025-14220MEDIUMORICO CD3510 File Upload path traversalEPSS 0.4%CVE-2024-24043MEDIUMDirectory Traversal vulnerability in Speedy11CZ MCRPX v.1.4.0 and before allows a local attacker to execute arbitrary code via a crafted filEPSS 0.4%CVE-2026-103648CRITICALImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in image-downloaderEPSS 0.4%CVE-2025-68649MEDIUMAn improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.EPSS 0.4%CVE-2026-35583MEDIUMEmissary has a Path Traversal via Blacklist Bypass in Configuration APIEPSS 0.4%CVE-2026-71557MEDIUMgo-git: Malicious reference names may modify files outside the reference storageEPSS 0.4%CVE-2026-77248HIGHMCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transportEPSS 0.4%CVE-2026-73658HIGHTrigger.dev: Cross-tenant object store read and write via URL path traversalEPSS 0.4%CVE-2025-14868HIGHCareer Section <= 1.6 - Cross-Site Request Forgery to Arbitrary File DeletionEPSS 0.4%CVE-2025-68279HIGHWeblate has an arbitrary file read via symbolic linksEPSS 0.4%CVE-2025-7450MEDIUMletseeqiji gorobbs API user.go ResetUserAvatar path traversalEPSS 0.4%CVE-2024-56142MEDIUMPath Traversal in pghoardEPSS 0.4%CVE-2026-70593MEDIUMGhost: Theme Upload Path TraversalEPSS 0.4%CVE-2026-2741LOWZip Slip Path Traversal on Node UnpackEPSS 0.4%CVE-2026-26228LOWVLC for Android < 3.7.0 Remote Access Path TraversalEPSS 0.4%CVE-2026-48099HIGHWsgiDAV encoded dot segments can escape filesystem share rootsEPSS 0.4%CVE-2025-13246MEDIUMshsuishang ShopSuite ModulithShop JwtAuthenticationFilter.java JwtAuthenticationFilter path traversalEPSS 0.4%CVE-2024-5040HIGHLCDS LAquis SCADA Path TraversalEPSS 0.4%CVE-2025-70028HIGHAn issue pertaining to CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') was discovered in Sunbird-Ed SEPSS 0.4%