Falhas do tipo CWE-22

6.002 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2026-96440HIGHFlowring Agentflow 4.0 - Improper Limitation of a Pathname to a Restricted Directory(Path Traversal)EPSS 0.3%CVE-2025-4748MEDIUMAbsolute path traversal in zip:unzip/1,2EPSS 0.3%CVE-2025-15491MEDIUMPost Slides <= 1.0.1 - Contributor+ Local File InclusionEPSS 0.3%CVE-2026-13426MEDIUMClient4 fails to validate path parametersEPSS 0.3%CVE-2024-53566MEDIUMAn issue in the action_listcategories() function of Sangoma Asterisk v22/22.0.0/22.0.0-rc1/22.0.0-rc2/22.0.0-pre1 allows attackers to executEPSS 0.3%CVE-2025-22238MEDIUMCVE-2025-22238 salt advisoryEPSS 0.3%CVE-2026-100533MEDIUMOpenClaw before 2026.8.1 Path Traversal via Unicode FallbackEPSS 0.3%CVE-2026-77757MEDIUMDirectorist 8.5 - 8.9.2 - Subscriber+ Arbitrary Image Move via REST v2 Listing SubmissionEPSS 0.3%CVE-2024-40712HIGHA path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege esEPSS 0.3%CVE-2026-103533LOWDavid-Crty databasement database-servers API Endpoint RestoreRequest.php 511 path traversalEPSS 0.3%CVE-2025-71427HIGHOffice-PowerPoint-MCP-Server through 2.0.7 Path Traversal via save_presentation and manage_imageEPSS 0.3%CVE-2026-42448LOWwormhole receive, with --output pointing at an existing directory can be path-traversedEPSS 0.3%CVE-2025-63680HIGHNero BackItUp in the Nero Productline is vulnerable to a path parsing/UI rendering flaw (CWE-22) that, in combination with Windows ShellExecEPSS 0.3%CVE-2026-0655MEDIUMPath Traversal on TP-Link Deco BE25EPSS 0.3%CVE-2026-93986LOWrclone before 1.75.1 Path Traversal via Directory Listing NamesEPSS 0.3%CVE-2025-50819HIGHDirectory traversal vulnerability in beiyuouo arxiv-daily thru 2025-05-06 (commit fad168770b0e68aef3e5acfa16bb2e7a7765d687) when parsing theEPSS 0.3%CVE-2026-11847MEDIUMIntegration Corp|iVEC-IEI Virtualization Edge Computer - Arbitrary File DeletionEPSS 0.3%CVE-2026-10278MEDIUMishayoyo excel-mcp read_file/write_file index.ts path traversalEPSS 0.3%CVE-2026-34657MEDIUMCAI Content Credentials | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)EPSS 0.3%CVE-2025-48395MEDIUMAn attacker with authenticated and privileged access could modify the contents of a non-sensitive file by traversing the path in the limitedEPSS 0.3%