Falhas do tipo CWE-22

6.042 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2026-9489HIGHNitroSense V3: Local Privilege Escalation (LPE) vulnerabilityEPSS 0.2%CVE-2026-52902MEDIUMAwxkit: path traversal via yaml !include directiveEPSS 0.2%CVE-2026-42549MEDIUMFlight: Path traversal in `make:controller` CLI creates arbitrary directories outside project rootEPSS 0.2%CVE-2026-63266MEDIUMArbitrary file write via calcext:data-mappings, sql provider and Firebird backup functionalityEPSS 0.2%CVE-2024-42187MEDIUMHCL BigFix Patch Download Plug-ins are affected by path traversal vulnerabilityEPSS 0.2%CVE-2026-47215MEDIUMSingularity: Incorrect path matching for 'limit container paths' directiveEPSS 0.2%CVE-2026-91801HIGHFoxit PDF Editor/Reader RichMedia Annotation Directory Traversal Remote Code Execution VulnerabilityEPSS 0.2%CVE-2022-20449MEDIUMIn writeApplicationRestrictionsLAr of UserManagerService.java, there is a possible overwrite of system files due to a path traversal error. EPSS 0.2%CVE-2026-82427HIGHApache Storm Nimbus: Path Traversal as the Supervisor User via Unsanitised Blobstore Map Local NameEPSS 0.2%CVE-2026-49356LOWBabel: Arbitrary File Read via sourceMappingURL Comment in @babel/coreEPSS 0.2%CVE-2022-50956MEDIUMWordPress Plugin amministrazione-aperta 3.7.3 Local File ReadEPSS 0.2%CVE-2026-88014MEDIUMrclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespaceEPSS 0.2%CVE-2026-48785MEDIUMApptainer: Incorrect path matching for 'limit container paths' directiveEPSS 0.1%CVE-2026-45380LOWbit7z: Path Traversal via Null Byte Injection from `gcount()` Off-by-One in `restoreSymlink()`EPSS 0.1%CVE-2025-59890HIGHImproper input sanitization in the file archives upload functionality of Eaton Galileo software allows traversing paths which could lead intEPSS 0.1%CVE-2026-9789HIGHNitroSense V3: Security Vulnerability InformationEPSS 0.1%CVE-2024-47292MEDIUMPath traversal vulnerability in the Bluetooth module Impact: Successful exploitation of this vulnerability may affect service confidentialitEPSS 0.1%CVE-2026-101295HIGHOc-mirror: oc-mirror: path traversal / arbitrary file write in operator catalog image extractionEPSS 0.1%CVE-2026-51882CRITICALThe OpenAI-compatible file upload endpoint `/v1/files` in Langchain-Chatchat 0.3.0 is vulnerable to path traversal. An attacker can write fiEPSS 0.1%CVE-2025-24268MEDIUMA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.4. AEPSS 0.1%