Falhas do tipo CWE-22

5.991 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2025-53505MEDIUMGroup-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a path traversal vulnerability. If this vulneraEPSS 0.3%CVE-2025-13876MEDIUMRareprob HD Video Player All Formats App com.rocks.music.videoplayer path traversalEPSS 0.3%CVE-2026-54336MEDIUMJumpServer: KoKo Web Terminal SFTP Path Traversal on Authorized AssetEPSS 0.3%CVE-2026-54613MEDIUMVvveb: Path Traversal in Revision Backup Reader/Deleter via Unsanitized theme ParameterEPSS 0.3%CVE-2023-46122LOWArbitrary file write via archive extraction (Zip Slip) vulnerability in sbtEPSS 0.3%CVE-2025-61647LOWUserInfoCard: Don't allow access to information about users who are suppressed if you don't have suppressor rightsEPSS 0.3%CVE-2026-77258HIGHMCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path()EPSS 0.3%CVE-2025-66206MEDIUMFrappe vulnerable to a path traversal allowing reading certain filesEPSS 0.3%CVE-2026-97226MEDIUMDbGate files-style Endpoint files.js fs.readFile path traversalEPSS 0.3%CVE-2026-97232MEDIUMvolotat Anagnorisis page.html start_streaming path traversalEPSS 0.3%CVE-2026-96678MEDIUMweiqingwen spring-boot-forum Avatar Upload NewUserFormValidator.java validate path traversalEPSS 0.3%CVE-2026-47121MEDIUMSparkle: Binary delta apply intermediate-symlink traversal in malicious .deltaEPSS 0.3%CVE-2026-101142MEDIUMEleveo Quality Management Questionnaire Audio Upload Scorecard.jsp path traversalEPSS 0.3%CVE-2024-47191HIGHpam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running EPSS 0.3%CVE-2026-22171HIGHOpenClaw < 2026.2.19 - Path Traversal in Feishu Media Temporary File NamingEPSS 0.3%CVE-2026-30915MEDIUMSFTPGo improperly sanitizes placeholders in group home directories/key prefixesEPSS 0.3%CVE-2026-15921LOWnvm path traversal via a malicious mirror's LTS codename writes outside the alias directoryEPSS 0.3%CVE-2026-0704MEDIUMIn affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field EPSS 0.3%CVE-2026-22762MEDIUMDell Avamar Server and Avamar Virtual Edition, versions prior to 19.10 SP1 with CHF338912, contain an Improper Limitation of a Pathname to aEPSS 0.3%CVE-2025-36598MEDIUMDell Avamar, versions prior to 19.12 with patch 338905, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path TraveEPSS 0.3%