CWE-73— External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.— MITRE CWE catalog
714 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-73page 1 of 15
- CVE-2020-1631CRITICALCVSS 8.8EG 9.8⚠ KEV2020-05-04
A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform local …
- CVE-2025-33053CRITICALCVSS 8.8EG 9.0⚠ KEV2025-06-10
External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network.
- CVE-2025-24054CRITICALCVSS 6.5EG 9.0⚠ KEV2025-03-11
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
- CVE-2025-0111CRITICALCVSS 6.5EG 9.0⚠ KEV2025-02-12
An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nob…
- CVE-2024-43451CRITICALCVSS 6.5EG 9.0⚠ KEV2024-11-12
NTLM Hash Disclosure Spoofing Vulnerability
- CVE-2026-101148CRITICALCVSS 10.0EG 10.02026-10-01
The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to create and download full site backups, …
- CVE-2026-20358CRITICALCVSS 10.0EG 10.02026-08-19
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address…
- CVE-2026-67429CRITICALCVSS 10.0EG 10.02026-07-29
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_with_env_config and its FLYTO_SANDBOX_DIR …
- CVE-2026-58192CRITICALCVSS 10.0EG 10.02026-07-08
Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 1.1.6, the Appium storage plugin exposes POST /storage/delete, whose handler passes the user-supplied name value di…
- CVE-2026-39907CRITICALCVSS 10.0EG 10.02026-04-14
Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on TCP port 1208 that accepts unsanitized file paths in the ReadLicense action's LFName parameter, allowing remote attacke…
- CVE-2026-27211CRITICALCVSS 10.0EG 10.02026-02-21
Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. Versions 34.0 through 50.0 arevulnerable to arbitrary host file exfiltration (constrained by process privileges) when using virtio-block devices backed by raw images. A mal…
- CVE-2024-13984CRITICALCVSS 10.0EG 10.02025-08-27
QiAnXin TianQing Management Center versions up to and including 6.7.0.4130 contain a path traversal vulnerability in the rptsvr component that allows unauthenticated attackers to upload files to arbitrary locations on the server. The /rpts…
- CVE-2025-71338CRITICALCVSS 9.8EG 10.02026-06-25
Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write files outside the storage directory. Attackers can use parent-directory sequences to escape the storag…
- CVE-2026-63343CRITICALCVSS 9.9EG 9.92026-08-21
Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path allows an authenticated Incus user to read or overwrite any file on …
- CVE-2026-72842CRITICALCVSS 9.9EG 9.92026-08-13
luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit path traversal via `/.%2E…
- CVE-2026-72841CRITICALCVSS 9.9EG 9.92026-08-13
luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory. Attackers can upload malicious pa…
- CVE-2026-14480CRITICALCVSS 9.9EG 9.92026-07-10
OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload workflow. The application stores an attacker‑supplied filename (prog_file) directly into the Programs.File database …
- CVE-2026-48753CRITICALCVSS 9.9EG 9.92026-06-26
Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary comm…
- CVE-2026-48752CRITICALCVSS 9.9EG 9.92026-06-26
Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution.…
- CVE-2026-48750CRITICALCVSS 9.9EG 9.92026-06-26
Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the instance. If `exe…
- CVE-2026-48749CRITICALCVSS 9.9EG 9.92026-06-26
Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 fixe…
- CVE-2026-45556CRITICALCVSS 9.9EG 9.92026-06-10
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /waf/<service>/<server_ip>/rule/<rule_id>/save accepts a config_file_name form field that is passed straight through…
- CVE-2026-9559CRITICALCVSS 9.9EG 9.92026-05-29
A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the validation logic allows file paths to escape the intended temporary directories. An…
- CVE-2026-40342CRITICALCVSS 9.9EG 9.92026-04-17
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-supplied engine name into a filesystem path without filtering path separa…
- CVE-2026-33309CRITICALCVSS 9.9EG 9.92026-03-19
Langflow is a tool for building and deploying AI-powered agents and workflows. Versions 1.2.0 through 1.8.1 have a bypass of the patch for CVE-2025-68478 (External Control of File Name), leading to the root architectural issue within `Loca…
- CVE-2026-28286CRITICALCVSS 9.9EG 9.92026-03-02
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.2-beta3, the application enforces restrictions in the frontend/UI to prevent users from creating files or folders in internal OS …
- CVE-2022-24900CRITICALCVSS 9.9EG 9.92022-04-29
Piano LED Visualizer is software that allows LED lights to light up as a person plays a piano connected to a computer. Version 1.3 and prior are vulnerable to a path traversal attack. The `os.path.join` call is unsafe for use with untruste…
- CVE-2026-16338CRITICALCVSS 8.8EG 9.92026-09-14
IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to perform an arbitrary file write due to improper validation of file paths.
- CVE-2026-90817CRITICALCVSS 9.8EG 9.82026-09-20
An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an unintend…
- CVE-2026-88899CRITICALCVSS 9.8EG 9.82026-09-10
knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to execute file operations outside the project root …
- CVE-2026-66302CRITICALCVSS 9.8EG 9.82026-09-08
External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.
- CVE-2026-86189CRITICALCVSS 9.8EG 9.82026-09-05
WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can …
- CVE-2026-59683CRITICALCVSS 9.8EG 9.82026-08-26
The OpenRGB network protocol allows to write attacker controlled strings into arbitrary file system paths (extension of CVE-2026-59682). This allows either a full system compromise from local or remote (if the daemon is running as root) or…
- CVE-2026-56705CRITICALCVSS 9.8EG 9.82026-08-25
Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP c…
- CVE-2026-53451CRITICALCVSS 9.8EG 9.82026-08-19
Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated save-waterfall-snapshot Socket.IO command passes attacker-controlled snap…
- CVE-2026-17184CRITICALCVSS 9.8EG 9.82026-08-14
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path.
- CVE-2026-17482CRITICALCVSS 9.8EG 9.82026-08-13
IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths.
- CVE-2026-52680CRITICALCVSS 9.8EG 9.82026-07-30
Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote attacker who can access the REST batch upload endpoint can provide path traversal sequence…
- CVE-2025-71334CRITICALCVSS 9.8EG 9.82026-06-25
Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missing validation that the chatflowId and chatId parameters are UUIDs or numbers in file handling operations. By supplying a…
- CVE-2025-71333CRITICALCVSS 9.8EG 9.82026-06-25
Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit path traversal in the chatId and chatflowId parameters to upl…
- CVE-2026-39006CRITICALCVSS 9.8EG 9.82026-06-15
An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component.
- CVE-2026-11526CRITICALCVSS 9.8EG 9.82026-06-14
GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle. GD::Image::_make_filehandle opens a filename argument with Perl's 2-arg open(), so a filename tha…
- CVE-2026-47643CRITICALCVSS 9.8EG 9.82026-06-09
External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network.
- CVE-2026-30281CRITICALCVSS 9.8EG 9.82026-03-31
An arbitrary file overwrite vulnerability in MaruNuri LLC v2.0.23 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
- CVE-2026-30276CRITICALCVSS 9.8EG 9.82026-03-31
An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
- CVE-2026-30903CRITICALCVSS 9.8EG 9.82026-03-11
External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via network access.
- CVE-2025-64712CRITICALCVSS 9.8EG 9.82026-02-04
The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. Prior to version 0.18.18, a path traversal vulnerability in the partition_ms…
- CVE-2020-37080CRITICALCVSS 9.8EG 9.82026-02-03
webTareas 2.0.p8 contains a file deletion vulnerability in the print_layout.php administration component that allows authenticated attackers to delete arbitrary files. Attackers can exploit the vulnerability by manipulating the 'atttmp1' p…
- CVE-2025-6237CRITICALCVSS 9.8EG 9.82025-09-18
A vulnerability in invokeai version v6.0.0a1 and below allows attackers to perform path traversal and arbitrary file deletion via the GET /api/v1/images/download/{bulk_download_item_name} endpoint. By manipulating the filename arguments, a…
- CVE-2025-54945CRITICALCVSS 9.8EG 9.82025-08-30
An external control of file name or path vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute arbitrary system commands via a malicious file by controlling the destination file path.
Map vulnerabilities like CWE-73 to your infrastructure
EchelonGraph correlates every CVE — across CWE-73 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →