CWE-426— Untrusted Search Path
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.— MITRE CWE catalog
732 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-426page 15 of 15
- CVE-2026-45772CRITICALCVSS 9.8EG 9.82026-05-15
Turborepo is a high-performance build system for JavaScript and TypeScript codebases. From 1.1.0 to before 2.9.14, Turborepo can be vulnerable to arbitrary code execution when run in untrusted repositories that contain malicious Yarn confi…
- CVE-2026-45792MEDIUMCVSS 5.5EG 5.52026-05-20
rtk filters and compresses command outputs before they reach your LLM context. Prior to 0.32.0, RTK (Rust Token Killer) improperly trusts project-local configuration files. RTK automatically loads .rtk/filters.toml from the working directo…
- CVE-2026-46710HIGHCVSS 7.8EG 7.82026-06-26
Notepad++ is a free and open-source source code editor. From 8.9.4 until 8.9.6, Notepad++ contains a local privilege escalation vulnerability in the installer. During installation, the installer invokes powershell.exe without using an abso…
- CVE-2026-47211HIGHCVSS 8.4EG 8.42026-05-29
Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. In versions prior to 0.39.0, if a user clones a malicious repository and runs Ouroboros commands wi…
- CVE-2026-47648HIGHCVSS 7.0EG 7.02026-06-09
Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.
- CVE-2026-48275HIGHCVSS 8.6EG 8.62026-07-14
Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…
- CVE-2026-48287HIGHCVSS 7.4EG 7.42026-07-14
CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of th…
- CVE-2026-48346HIGHCVSS 7.9EG 7.92026-07-14
Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious fil…
- CVE-2026-48391HIGHCVSS 8.2EG 8.22026-07-28
Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitati…
- CVE-2026-48395HIGHCVSS 8.6EG 8.62026-07-28
Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this iss…
- CVE-2026-48565HIGHCVSS 7.8EG 7.82026-06-09
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
- CVE-2026-49145HIGHCVSS 7.5EG 7.52026-07-08
App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc. ack searches up the directory hierarchy from the current directory for a project .ackrc and loads its options. The project-source option …
- CVE-2026-4962HIGHCVSS 7.0EG 7.02026-03-27
A security flaw has been discovered in UltraVNC up to 1.6.4.0. Affected by this issue is some unknown functionality in the library version.dll of the component Service. The manipulation results in uncontrolled search path. The attack needs…
- CVE-2026-53819HIGHCVSS 8.8EG 8.82026-06-11
OpenClaw before 2026.5.27 contains an arbitrary code execution vulnerability in skill install flows where workspace .env files can override the Homebrew executable selection. Attackers with access to trusted operator workspaces can execute…
- CVE-2026-53842HIGHCVSS 7.1EG 7.12026-06-16
OpenClaw before 2026.5.2 contains an environment variable injection vulnerability allowing workspace .env files to influence Python runtime selection through CLOUDSDK_PYTHON during Gmail setup gcloud execution. Attackers with repository ac…
- CVE-2026-53846HIGHCVSS 7.1EG 7.12026-06-16
OpenClaw before 2026.4.29 contains a path traversal vulnerability in the install helper that allows workspace .env files to override the npm_execpath configuration used for bundled runtime dependency installation. Attackers with workspace …
- CVE-2026-53858HIGHCVSS 7.1EG 7.12026-06-16
OpenClaw before 2026.5.2 contains an environment variable injection vulnerability where workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots. Attackers can manipulate the STATE_DIRECTORY variable to load runtime …
- CVE-2026-53865HIGHCVSS 7.1EG 7.12026-06-16
OpenClaw before 2026.5.2 contains a path traversal vulnerability in maintenance task execution that allows workspace-derived service paths to influence trash command selection. Attackers can execute unintended local executables from operat…
- CVE-2026-54055MEDIUMCVSS 5.0EG 5.02026-06-12
Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.2, a local privilege escalation vulnerability exists in kitty's file transmission protocol where a child process running in the terminal can write to arbitrary files o…
- CVE-2026-55522HIGHCVSS 7.8EG 7.82026-08-05
PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow "include" feature is vulnerable to code execution. Workflow._execute_include() implicitly…
- CVE-2026-55769CRITICALCVSS 9.4EG 9.42026-08-20
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG opened superuser connections without pinning search_path in fillDefaultParameters in pkg/manageme…
- CVE-2026-56174HIGHCVSS 7.8EG 7.82026-08-11
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
- CVE-2026-57097MEDIUMCVSS 6.8EG 6.82026-07-14
Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.
- CVE-2026-57919HIGHCVSS 7.8EG 7.82026-06-29
PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DACL that grants GENERIC_READ and GENERIC_WRITE permissions to all authenticated users. A low-privileged local attacker c…
- CVE-2026-63093HIGHCVSS 8.8EG 8.82026-07-17
Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbitrary code execution by placing a malicious git.exe file in the repository root directory. When a developer clones and o…
- CVE-2026-6421HIGHCVSS 7.0EG 7.02026-04-17
A vulnerability has been found in Mobatek MobaXterm Home Edition up to 26.1. This affects an unknown part in the library msimg32.dll. The manipulation leads to uncontrolled search path. An attack has to be approached locally. The attack is…
- CVE-2026-6901HIGHCVSS 7.7EG 7.72026-07-06
Untrusted Search Path vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before R 4.4-01P5.
- CVE-2026-7309MEDIUMCVSS 4.3EG 4.32026-04-28
A flaw was found in the OpenShift Container Platform build system. A user with the `edit` ClusterRole can inject arbitrary environment variables, such as `LD_PRELOAD` or `http_proxy`, into `docker-build` containers through the `buildconfig…
- CVE-2026-74872CRITICALCVSS 9.8EG 9.82026-08-17
openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can place malicious .s…
- CVE-2026-75768HIGHCVSS 7.8EG 7.82026-08-25
Substance3D - Painter is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitat…
- CVE-2026-78155CRITICALCVSS 9.9EG 9.92026-08-23
privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges
- CVE-2026-78680HIGHCVSS 7.8EG 7.82026-08-25
NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot binary in dependencygraph.dot2img and AlignedSent._repr_svg_, allowing attackers to execute arbitrary code by placing a malicious dot binary in…
Map vulnerabilities like CWE-426 to your infrastructure
EchelonGraph correlates every CVE — across CWE-426 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →