CWE-73— External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.— MITRE CWE catalog
597 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-73page 11 of 12
- CVE-2026-48520MEDIUMCVSS 6.1EG 6.12026-06-16
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.10.0, the "Shareable Playground" (or "Public Flows" in code) contains a potential arbitrary file-read vulnerability, depending on the exact flow conf…
- CVE-2026-48720HIGHCVSS 8.8EG 8.82026-06-24
Warp is an agentic development environment. From 0.2025.03.05.08.02.stable_00 until 0.2026.05.06.15.42.stable_01, Warp accepts non-inline `OSC 1337;File` payloads from terminal output and materialize the decoded payload as a local file wit…
- CVE-2026-48749CRITICALCVSS 9.9EG 9.92026-06-26
Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 fixe…
- CVE-2026-48750CRITICALCVSS 9.9EG 9.92026-06-26
Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the instance. If `exe…
- CVE-2026-48752CRITICALCVSS 9.9EG 9.92026-06-26
Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution.…
- CVE-2026-48753CRITICALCVSS 9.9EG 9.92026-06-26
Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary comm…
- CVE-2026-48798HIGHCVSS 7.1EG 7.12026-08-12
SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, DirectoryInfo directoryInfo) trusts file and directory names returned by a remote SCP server and combines them with the req…
- CVE-2026-48920HIGHCVSS 8.8EG 8.82026-05-27
Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attribute, without restrictions on the image URLs that can be inlined, allowing attackers able t…
- CVE-2026-49145HIGHCVSS 7.5EG 7.52026-07-08
App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc. ack searches up the directory hierarchy from the current directory for a project .ackrc and loads its options. The project-source option …
- CVE-2026-49358LOWCVSS 3.0EG 3.02026-06-19
PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `AbstractGenerator::$temporaryFiles` is a public array, and `removeTemporaryFiles()` — invoked from `__destruct()` and from a regi…
- CVE-2026-49360HIGHCVSS 7.8EG 7.82026-07-02
Recce is a data-validation toolkit for enhanced dbt (data build tool) PR review. Prior to version 1.50.0, OSS server deployments that expose the server to an untrusted network without authentication are vulnerable to unauthenticated SQL ex…
- CVE-2026-49441CRITICALCVSS 9.1EG 9.12026-08-19
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.3.0 until 4.14.6 and 5.0.0-beta3, the non-merged branch of process_files_from_worker() in framework/wazuh/core/cluster/master.py trusts a …
- CVE-2026-50006CRITICALCVSS 9.1EG 9.12026-07-14
Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server Mode ## Summary Anyquery's `server` mode does not disable or restrict native SQLite disk manipulation commands…
- CVE-2026-50148CRITICALCVSS 9.1EG 9.12026-07-15
Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user with permission to add or edit a database connection can achi…
- CVE-2026-50162MEDIUMCVSS 6.9EG 6.92026-07-01
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, resolveWritePath() in content/file/file.go uses a lexical filepath.Rel check for workingDir and does not account for symlink traversal, so when AllowPathTraversalOnWrite=f…
- CVE-2026-50462HIGHCVSS 7.8EG 7.82026-07-14
External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- CVE-2026-5053HIGHCVSS 7.1EG 7.12026-04-11
NoMachine External Control of File Path Arbitrary File Deletion Vulnerability. This vulnerability allows local attackers to delete arbitrary files on affected installations of NoMachine. An attacker must first obtain the ability to execute…
- CVE-2026-5054HIGHCVSS 7.8EG 7.82026-04-11
NoMachine External Control of File Path Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine. An attacker must first obtain the ability to execute…
- CVE-2026-5210HIGHCVSS 7.3EG 7.32026-03-31
A vulnerability was detected in SourceCodester Leave Application System 1.0. This affects an unknown part. Performing a manipulation of the argument page results in file inclusion. Remote exploitation of the attack is possible. The exploit…
- CVE-2026-52680CRITICALCVSS 9.8EG 9.82026-07-30
Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote attacker who can access the REST batch upload endpoint can provide path traversal sequence…
- CVE-2026-52872HIGHCVSS 8.8EG 8.82026-08-18
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.5.0, the downloadSubtitleFile utility in src/ipc/downloads.js, reached through the run-download IPC channel, accepts a renderer-supplied s…
- CVE-2026-52875HIGHCVSS 8.4EG 8.42026-08-18
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.6.0, the perform-scheduled-backup IPC handler in src/ipc/storage.js takes settings.path from a renderer-supplied object and uses the resul…
- CVE-2026-53449MEDIUMCVSS 6.0EG 6.02026-07-10
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, the psd print sessions dump CLI command in coturn takes a filename argument and directly passes it to fopen with no path validation. An authenticated adm…
- CVE-2026-53451CRITICALCVSS 9.8EG 9.82026-08-19
Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated save-waterfall-snapshot Socket.IO command passes attacker-controlled snap…
- CVE-2026-53632MEDIUMCVSS 5.5EG 5.52026-06-15
launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a UNC path is opened, Windows automatically attemp…
- CVE-2026-53648MEDIUMCVSS 5.1EG 5.12026-07-06
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.1, downloadable product files are stored using a deterministic filename-derived path. When an administrator uploads a file for a downloadable pro…
- CVE-2026-53915HIGHCVSS 8.8EG 8.82026-06-19
In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration
- CVE-2026-54108MEDIUMCVSS 6.5EG 6.52026-07-14
External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-54134HIGHCVSS 7.0EG 7.02026-06-23
OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, OctoPrint's custom Tornado upload handler and Flask with Werkzeug parse request parameters differently, allowing an attacker with FILE_U…
- CVE-2026-54200HIGHCVSS 8.4EG 8.42026-08-07
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability in the send email, fax, SMS, etc. functionality. By specifying an '@@attach' command in the form field 'scjob', files can be attached to a me…
- CVE-2026-54629HIGHCVSS 7.5EG 7.52026-07-14
Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode ## Summary Anyquery's `server` mode lacks input sanitization and access control over its built-in SQLite virtual table modules (e.g., `csv_reader…
- CVE-2026-55002HIGHCVSS 8.8EG 8.82026-07-14
External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.
- CVE-2026-55477HIGHCVSS 7.2EG 7.22026-06-25
3X-UI is a web control panel for managing Xray-core servers. Prior to 3.3.1, an authenticated administrator can abuse the database import functionality to achieve arbitrary file write on the host by modifying Xray configuration values stor…
- CVE-2026-55527HIGHCVSS 7.1EG 7.12026-08-25
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the FileMemory constructor joins unsanitized user_id into self.user_path. A caller supplying ../ or path separators can escape the memory directory and write JSON da…
- CVE-2026-55609HIGHCVSS 7.1EG 7.12026-08-25
sublinear-time-solver is a Rust and WebAssembly library for solving asymmetric diagonally dominant systems in sublinear time. Prior to consciousness-explorer 1.1.2 and sublinear-time-solver 1.6.0, the export_state and import_state tools in…
- CVE-2026-55628MEDIUMCVSS 5.5EG 5.52026-07-01
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-26he, the `-concatenate` operation is missing policy checks, potentially resulting in both reading and writing to pat…
- CVE-2026-55699MEDIUMCVSS 6.5EG 6.52026-06-25
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, Manifest bin object keys such as "", ".", and ".." passed pnpm's bin-name guard. When a malicious package was installed globally, later global remove, update, or add-replacement flows…
- CVE-2026-55700HIGHCVSS 7.1EG 7.12026-06-25
pnpm is a package manager. From 11.3.0 until 11.5.3, `pnpm stage download` derived a local filename from registry-controlled package name and version fields. A crafted manifest could escape the selected download directory and overwrite ano…
- CVE-2026-56390MEDIUMCVSS 6.3EG 6.32026-07-29
GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %header allow specifying file paths, which are accepted without restriction and override caller‑supplied output options. When processing…
- CVE-2026-56452HIGHCVSS 7.5EG 7.52026-07-20
Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. The implementation of receiving files or directories via SCP did not validate filenames in SCP "C" o…
- CVE-2026-56705CRITICALCVSS 9.8EG 9.82026-08-25
Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP c…
- CVE-2026-57898CRITICALCVSS 9.0EG 9.02026-07-14
In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauthenticated arbitrary file write through the AAS thumbnail API. The AAS thumbnail upload…
- CVE-2026-57916MEDIUMCVSS 4.6EG 4.62026-07-27
proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can prepare arbitrary certificate with CPS URI pointing to a local executable file or any URL, sign a document with it, and send it t…
- CVE-2026-5809HIGHCVSS 7.1EG 7.12026-04-11
The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.2. This is due to a two-step logic flaw: the topic_add() and topic_edit() action handlers accept arbitrary user-supplied dat…
- CVE-2026-58192HIGHCVSS 8.6EG 8.62026-07-08
Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 1.1.6, the Appium storage plugin exposes POST /storage/delete, whose handler passes the user-supplied name value di…
- CVE-2026-5821HIGHCVSS 8.1EG 8.12026-07-02
The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to and including 1.7.4. This is due to insufficient path validation in the Image_Backup::remove() function where backup file paths stored in p…
- CVE-2026-58293HIGHCVSS 8.1EG 8.12026-07-03
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- CVE-2026-58484HIGHCVSS 7.1EG 7.12026-07-20
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.listBackups()` reads each backup's `_manifest.json` and trusts the manifest's `path` field. `EnvironmentManager.pruneBackups()` later…
- CVE-2026-59194HIGHCVSS 7.1EG 7.12026-07-06
pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patch entry could resolve outside the configured patches directory and cause pnpm patch-remove to delete an arbitrary reachable file. This vulnerability is fixed in 10.34.4 …
- CVE-2026-59196HIGHCVSS 7.1EG 7.12026-07-06
pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockfile alias could be joined directly under a hoisted node_modules directory. Traversal aliases could escape that directory, while reserved aliases such as .bin or .pnpm c…
Map vulnerabilities like CWE-73 to your infrastructure
EchelonGraph correlates every CVE — across CWE-73 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →