CWE-73— External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.— MITRE CWE catalog
714 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-73page 10 of 15
- CVE-2026-45725HIGHCVSS 7.1EG 7.12026-05-27
compliance-trestle is a tooling platform for managing compliance as code. Prior to versiions 3.12.2 and 4.0.3, the compliance-trestle library's remote fetching cache mechanism (HTTPSFetcher and SFTPFetcher) constructs the local cache file …
- CVE-2026-44641HIGHCVSS 7.1EG 7.12026-05-15
Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.8.12, Microsoft APM normalizes marketplace plugins by copying plugin components referenced in plugin.json into .apm/. The manifest fields agents…
- CVE-2026-5809HIGHCVSS 7.1EG 7.12026-04-11
The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.2. This is due to a two-step logic flaw: the topic_add() and topic_edit() action handlers accept arbitrary user-supplied dat…
- CVE-2026-5053HIGHCVSS 7.1EG 7.12026-04-11
NoMachine External Control of File Path Arbitrary File Deletion Vulnerability. This vulnerability allows local attackers to delete arbitrary files on affected installations of NoMachine. An attacker must first obtain the ability to execute…
- CVE-2026-25605HIGHCVSS 7.1EG 7.12026-03-10
A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The affected application performs file deletion without properly validating the file path or target. An attacker could delete files or sockets that the affecte…
- CVE-2026-27115HIGHCVSS 7.1EG 7.12026-02-20
ADB Explorer is a fluent UI for ADB on Windows. Versions 0.9.26020 and below have an unvalidated command-line argument that allows any user to trigger recursive deletion of arbitrary directories on the Windows filesystem. ADB Explorer acce…
- CVE-2025-68478HIGHCVSS 7.1EG 7.12025-12-19
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, if an arbitrary path is specified in the request body's `fs_path`, the server serializes the Flow object into JSON and creates/overwrite…
- CVE-2024-43615HIGHCVSS 7.1EG 7.12024-10-08
Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
- CVE-2024-43581HIGHCVSS 7.1EG 7.12024-10-08
Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
- CVE-2023-36634HIGHCVSS 7.1EG 7.12023-09-13
An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-U 7.0.0, 6.2.0 through 6.2.5, 6.0 all versions, 5.4 all versions may allow an authenticated attacker to…
- CVE-2023-1070HIGHCVSS 7.1EG 7.12023-02-27
External Control of File Name or Path in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22.
- CVE-2026-69383HIGHCVSS 7.0EG 7.02026-09-08
External control of file name or path in Windows Shell allows an authorized attacker to elevate privileges locally.
- CVE-2026-81726HIGHCVSS 7.0EG 7.02026-08-27
NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. Attackers can read or write files outside allowed sandbox roots thr…
- CVE-2026-34492HIGHCVSS 7.0EG 7.02026-08-14
External control of file name or path vulnerability in Johnson Controls Airwall allows : File Manipulation. This issue affects Airwall: before 4.1.
- CVE-2026-54134HIGHCVSS 7.0EG 7.02026-06-23
OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, OctoPrint's custom Tornado upload handler and Flask with Werkzeug parse request parameters differently, allowing an attacker with FILE_U…
- CVE-2026-26158HIGHCVSS 7.0EG 7.02026-02-11
A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction directory by crafting a malicious tar archive containing unvalidated hardlink or symlink entries. If the tar archive is e…
- CVE-2026-26157HIGHCVSS 7.0EG 7.02026-02-11
A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended direct…
- CVE-2026-50162MEDIUMCVSS 6.9EG 6.92026-07-01
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, resolveWritePath() in content/file/file.go uses a lexical filepath.Rel check for workingDir and does not account for symlink traversal, so when AllowPathTraversalOnWrite=f…
- CVE-2026-34030MEDIUMCVSS 6.9EG 6.92026-06-15
The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, does not sufficiently validate the branch code when a new branch is created. The branch code is later used in multiple application functions, including filesystem path…
- CVE-2026-47425MEDIUMCVSS 6.9EG 6.92026-06-01
Rattler is a library that provides common functionality used within the conda ecosystem. Prior to version 0.43.2, `EntryPoint::FromStr` in `rattler_conda_types` performs only `.trim()` on the `command` field before the linker joins it onto…
- CVE-2022-4983MEDIUMCVSS 6.9EG 6.92025-11-12
TEC-IT TBarCode version 11.15 contains a vulnerability in the TBarCode11.ocx ActiveX/OCX control's licensing handling (INI-file based) that can be abused to cause remote creation of files on the host filesystem. Depending on where files ca…
- CVE-2025-29930MEDIUMCVSS 6.9EG 6.92025-03-18
imFAQ is an advanced questions and answers management system for ImpressCMS. Prior to 1.0.1, if the $_GET['seoOp'] parameter is manipulated to include malicious input (e.g., seoOp=php://filter/read=convert.base64-encode/resource=/var/www/h…
- CVE-2025-0109MEDIUMCVSS 6.9EG 6.92025-02-12
An unauthenticated file deletion vulnerability in the Palo Alto Networks PAN-OS management web interface enables an unauthenticated attacker with network access to the management web interface to delete certain files as the “nobody” us…
- CVE-2026-10726MEDIUMCVSS 6.8EG 6.82026-09-30
Cato Windows SDP Client before version 6.12.6 contains an arbitrary file disclosure vulnerability. A low-privileged local user can cause the Windows service, running as Local System, to read and disclose arbitrary local files due to improp…
- CVE-2026-12513MEDIUMCVSS 6.8EG 6.82026-08-28
The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.68 do not properly sanitize a file path taken from a frontend file submission and their single-pass traversal filter is bypassable, allowing una…
- CVE-2026-65939MEDIUMCVSS 6.8EG 6.82026-08-12
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.
- CVE-2026-59807MEDIUMCVSS 6.8EG 6.82026-07-08
Composio SDK before 0.2.32-beta.283 contains a path validation bypass vulnerability that allows attackers to read and exfiltrate sensitive files by exploiting a missing assertSafeFileUploadPath check in the readFileFromDisk function within…
- CVE-2026-35593MEDIUMCVSS 6.8EG 6.82026-05-20
Trilium Notes is an open-source, cross-platform hierarchical note taking application for building large personal knowledge bases. Versions 0.102.1 and prior are vulnerable to Local File Inclusion, allowing an authenticated attacker to read…
- CVE-2025-13320MEDIUMCVSS 6.8EG 6.82025-12-12
The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, 2.9.12. This is due to insufficient validation of user-supplied file paths in the profile update functionality combined…
- CVE-2024-12058MEDIUMCVSS 6.8EG 6.82025-02-11
External control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to read arbitrary files.
- CVE-2024-25117MEDIUMCVSS 6.8EG 6.82024-02-21
php-svg-lib is a scalable vector graphics (SVG) file parsing/rendering library. Prior to version 0.5.2, php-svg-lib fails to validate that font-family doesn't contain a PHAR url, which might leads to RCE on PHP < 8.0, and doesn't validate …
- CVE-2025-1686MEDIUMCVSS 4.9EG 6.82025-02-27
Versions of the package io.pebbletemplates:pebble from 0 and before 4.1.0 are vulnerable to External Control of File Name or Path via the include tag. A high privileged attacker can access sensitive local files by crafting malicious notifi…
- CVE-2026-79814MEDIUMCVSS 6.7EG 6.72026-10-06
An arbitrary file write vulnerability in the ClearPass Policy Manager OnGuard agent could allow malicious users on a local instance to elevate their user privileges if certain preconditions outside of the attacker's control are met. Succes…
- CVE-2026-102141MEDIUMCVSS 6.7EG 6.72026-09-30
Two Kiteworks Core cluster-management operations did not validate file paths supplied to them, so an attacker holding root on one node of a cluster could write files as root onto another node and cause them to be executed there. Exploitati…
- CVE-2026-42866MEDIUMCVSS 6.7EG 6.72026-05-11
Tookie is a advanced OSINT information gathering tool. Prior to 4.1fix, modules/modules.py's write_txt, write_csv, write_json, and (commented-but-shipping) scan_file helpers open their output as open(f"{user}.<ext>"), where user comes unsa…
- CVE-2026-27008MEDIUMCVSS 6.7EG 6.72026-02-20
OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a bug in `download` skill installation allowed `targetDir` values from skill frontmatter to resolve outside the per-skill tools directory if not strictly validated. In the ad…
- CVE-2025-20614MEDIUMCVSS 6.7EG 6.72025-11-11
External control of file name or path for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined …
- CVE-2025-26684MEDIUMCVSS 6.7EG 6.72025-05-13
External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
- CVE-2024-38173MEDIUMCVSS 6.7EG 6.72024-08-13
Microsoft Outlook Remote Code Execution Vulnerability
- CVE-2024-38049MEDIUMCVSS 6.6EG 6.62024-07-09
Windows Distributed Transaction Coordinator Remote Code Execution Vulnerability
- CVE-2026-108694MEDIUMCVSS 6.5EG 6.52026-10-11
ConvertX through 0.19.0 contains an arbitrary file read vulnerability that allows authenticated users to read server files because src/converters/pandoc.ts invokes Pandoc without the --sandbox flag. Attackers can upload a reStructuredText …
- CVE-2026-102146MEDIUMCVSS 6.5EG 6.52026-09-30
An authenticated Email Protection Gateway administrator holding only limited, delegated permissions could write files with attacker-controlled content to arbitrary locations accessible to the Email Protection Gateway service account. This …
- CVE-2026-101126MEDIUMCVSS 6.5EG 6.52026-09-29
Joomla Extension - balbooa.com - File meta data tampering in Balbooa Forms < 2.4.3.4 - The final form submission processes JSON arrays per upload field, checking only that IDs are numeric. Client-supplied filenames and display names are tr…
- CVE-2026-92164MEDIUMCVSS 6.5EG 6.52026-09-23
Streamlink is a CLI utility which pipes video streams from various services into a video player. Prior to 8.6.0, HTTPSession mounts a FileAdapter for the file scheme and inherits redirect handling from requests.Session without rejecting cr…
- CVE-2026-77247MEDIUMCVSS 6.5EG 6.52026-09-22
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira and Confluence upload tools interpret caller-controlled path arguments on the MCP server and open those files before…
- CVE-2026-76553MEDIUMCVSS 6.5EG 6.52026-09-16
The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a path taken from stored, user-supplied data before recursively deleting the directory it resolves to, allowing users to whom an administrator has delegated a WP Im…
- CVE-2026-85603MEDIUMCVSS 6.5EG 6.52026-09-04
Grav versions before 1.10.55 contain a path traversal vulnerability in the admin plugin's Save As action that fails to validate the language code parameter. An authenticated admin user with admin.pages.create permission can supply director…
- CVE-2026-75602MEDIUMCVSS 6.5EG 6.52026-09-03
OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download feature at POST /api/fs/add_offline_download with tool: "SimpleHttp" accepts an attacker-supplied URL and saves its bytes under a per-…
- CVE-2026-66324MEDIUMCVSS 6.5EG 6.52026-08-28
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-78679MEDIUMCVSS 6.5EG 6.52026-08-25
GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file=<path> to read arbit…
Map vulnerabilities like CWE-73 to your infrastructure
EchelonGraph correlates every CVE — across CWE-73 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →