Falhas do tipo CWE-22

5.987 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2024-25156MEDIUMPath traversal in GoAnywhere MFT 7.4.1 and EarlierEPSS 0.4%CVE-2026-96824MEDIUMWordPress Template Kit – Import plugin <= 1.0.16 - Arbitrary File Deletion vulnerabilityEPSS 0.4%CVE-2026-33220MEDIUMWeblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repositoryEPSS 0.4%CVE-2025-54748MEDIUMWordPress MapSVG Plugin < 8.6.12 - Arbitrary File Download VulnerabilityEPSS 0.4%CVE-2024-7263CRITICALArbitrary Code Execution in WPS OfficeEPSS 0.4%CVE-2024-30143MEDIUMA path traversal vulnerability in HCL AppScan Traffic RecorderEPSS 0.4%CVE-2026-45711MEDIUMMailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDsEPSS 0.4%CVE-2022-28541MEDIUMUncontrolled search path element vulnerability in Samsung Update prior to version 3.0.77.0 allows attackers to execute arbitrary code as SamEPSS 0.4%CVE-2025-61653LOWExtension:TextExtracts does not check for authorizeRead when returning extractsEPSS 0.4%CVE-2026-102810HIGHMarmite through 0.4.2 Path Traversal via Development ServerEPSS 0.4%CVE-2026-73079HIGHSub2API: Path traversal in the Responses subpath routes lets an authenticated tenant relay requests to arbitrary upstream endpoints using pooled account credentialsEPSS 0.4%CVE-2026-51907HIGHIn TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vulnerability allows attackers to write imaEPSS 0.4%CVE-2026-35487MEDIUMtext-generation-webui has a Path Traversal in load_prompt() — .txt file read without authenticationEPSS 0.4%CVE-2026-49339HIGHPath traversal in getPlaylist/deletePlaylist bypasses ownership check: any authenticated user can read or delete any other user's playlistEPSS 0.4%CVE-2026-41843MEDIUMSpring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFluxEPSS 0.4%CVE-2026-40090HIGHZarf has a Path Traversal via Malicious Package Metadata.Name — Arbitrary File WriteEPSS 0.4%CVE-2025-0614MEDIUMInput validation vulnerability in Qualifio's Wheel of FortuneEPSS 0.4%CVE-2026-73291HIGHSeerr: Path traversal to RCE via /avatarproxy image cache filename from upstream ETagEPSS 0.4%CVE-2026-84842HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.4%CVE-2026-41691MEDIUMi18next-http-backend has Path Traversal & URL Injection via Unsanitised lng/nsEPSS 0.4%