Falhas do tipo CWE-22

5.988 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2026-34726MEDIUMCopier `_subdirectory` allows template root escape via parent-directory traversalEPSS 0.4%CVE-2026-104417MEDIUMGhost 1.20.0 before 6.64.0 Path Traversal via Locale SettingEPSS 0.4%CVE-2020-1737HIGHA flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip moEPSS 0.4%CVE-2025-8406MEDIUMPath Traversal in zenml-io/zenmlEPSS 0.4%CVE-2026-67295MEDIUMFreeRDP before 3.29.0 Path Traversal via drive redirectionEPSS 0.4%CVE-2023-41057MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in hyper-bump-itEPSS 0.4%CVE-2025-14293MEDIUMWP Job Portal <= 2.4.0 - Authenticated (Subscriber+) Arbitrary File ReadEPSS 0.4%CVE-2025-68862HIGHWordPress Woo File Dropzone plugin <= 1.1.7 - Arbitrary File Deletion vulnerabilityEPSS 0.4%CVE-2026-77193HIGHeesy_ID2WP – Publish InDesign HTML5 <= 1.0.3 - Unauthenticated Path Traversal to Arbitrary File Read via 'id2wp_path' Query ParameterEPSS 0.4%CVE-2025-68921HIGHSteelSeries Nahimic 3 1.10.7 allows Directory traversal.EPSS 0.4%CVE-2025-27098MEDIUMUnwanted access to the entire file system vulnerability due to a missing check in `staticFiles` HTTP handler in graphql-meshEPSS 0.4%CVE-2026-22661HIGHprompts.chat Path Traversal via Skill File HandlingEPSS 0.4%CVE-2024-46327MEDIUMAn issue in the Http_handle object of VONETS VAP11G-300 v3.3.23.6.9 allows attackers to access sensitive files via a directory traversal.EPSS 0.4%CVE-2022-4773LOWcloudsync LocalFilesystemConnector.java getItem path traversalEPSS 0.4%CVE-2026-13224HIGHFireware OS Path Traversal in WebUI Management Agent Allows Arbitrary Local File ReadEPSS 0.4%CVE-2026-23942MEDIUMSFTP root escape via component-agnostic prefix check in ssh_sftpdEPSS 0.4%CVE-2025-61649LOWUserInfoCard: Check that performing user has permission to view log entries for number of past blocksEPSS 0.4%CVE-2026-86071LOWJunrar: LocalFolderExtractor mkdir escape allows directory creation outside extraction rootEPSS 0.4%CVE-2026-11769MEDIUMOperator - Namespaced User Path TraversalEPSS 0.4%CVE-2026-54014MEDIUMOpen WebUI: Sibling-Prefix Path Traversal via /cache/{path} in open-webui/open-webuiEPSS 0.4%