CWE-73— External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.— MITRE CWE catalog
714 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-73page 5 of 15
- CVE-2024-9575HIGHCVSS 8.5EG 8.52024-10-09
Local File Inclusion vulnerability in pretix Widget WordPress plugin pretix-widget on Windows allows PHP Local File Inclusion. This issue affects pretix Widget WordPress plugin: from 1.0.0 through 1.0.5.
- CVE-2026-87685HIGHCVSS 8.4EG 8.42026-10-08
An arbitrary file manipulation vulnerability exists in the WebTools management interface of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When processing configuration transfer requests, the application fails to pro…
- CVE-2026-86671HIGHCVSS 8.4EG 8.42026-10-05
In Eclipse Che versions 7.29.0 and later, the GET `/api/scm/resolve` and `POST /api/factory/resolver` endpoints pass an attacker-controlled URL to `URLFetcher.fetch()`, which calls `new URL(url).openConnection()` with no scheme or host all…
- CVE-2026-104809HIGHCVSS 8.4EG 8.42026-10-05
DigitalCanion has discovered a vulnerability that allows an attacker to cause the system to load an attacker-controlled .so file instead of the expected legitimate module. The loading mechanism relies on a predictable module name without a…
- CVE-2026-83603HIGHCVSS 8.4EG 8.42026-09-22
Netdata is an open source observability tool. Prior to 2.10.4, the setuid-root ndsudo helper command fail2ban-client-status-socket in src/collectors/utils/ndsudo.c accepts a caller-controlled --socket_path from the low-privileged netdata s…
- CVE-2026-52875HIGHCVSS 8.4EG 8.42026-08-18
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.6.0, the perform-scheduled-backup IPC handler in src/ipc/storage.js takes settings.path from a renderer-supplied object and uses the resul…
- CVE-2026-55062HIGHCVSS 8.4EG 8.42026-08-17
uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go concatenates an unvalidated hook filename with the selected hooks directory, allowing parent-directory compon…
- CVE-2026-54200HIGHCVSS 8.4EG 8.42026-08-07
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability in the send email, fax, SMS, etc. functionality. By specifying an '@@attach' command in the form field 'scjob', files can be attached to a me…
- CVE-2026-12070HIGHCVSS 8.4EG 8.42026-08-07
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to an arbitrary file deletion vulnerability in the send email, fax, SMS, etc. functionality. By specifying an @@COMMENTFILE command in the form field scjob, any file on the system …
- CVE-2026-46345HIGHCVSS 8.4EG 8.42026-05-28
compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the `-o/--output` argument in `trestle author jinja` allows writing files outside the intended workspace. The application does no…
- CVE-2026-42881HIGHCVSS 8.4EG 8.42026-05-14
STIGQter is an open-source reimplementation of DISA's STIG Viewer. From 0.1.2 to before 1.2.7, an attacker can achieve local code execution (LCE) with the privileges of the user running STIGQter. This requires user interaction: the victim …
- CVE-2026-30292HIGHCVSS 8.4EG 8.42026-04-01
An arbitrary file overwrite vulnerability in Docudepot PDF Reader: PDF Viewer APP v1.0.34 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
- CVE-2026-30291HIGHCVSS 8.4EG 8.42026-04-01
An arbitrary file overwrite vulnerability in Ora Tools PDF Reader ' Reader & Editor APPv4.3.5 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
- CVE-2026-30289HIGHCVSS 8.4EG 8.42026-04-01
An arbitrary file overwrite vulnerability in Tinybeans Private Family Album App v5.9.5-prod allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
- CVE-2026-30287HIGHCVSS 8.4EG 8.42026-04-01
An arbitrary file overwrite vulnerability in Deep Thought Industries ACE Scanner PDF Scanner v1.4.5 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information expos…
- CVE-2011-10030HIGHCVSS 8.4EG 8.42025-08-20
Foxit PDF Reader < 4.3.1.0218 exposes a JavaScript API function, createDataObject(), that allows untrusted PDF content to write arbitrary files anywhere on disk. By embedding a malicious PDF that calls this API, an attacker can drop exec…
- CVE-2024-10210HIGHCVSS 8.4EG 8.42025-03-25
An External Control of File Name or Path vulnerability in the APROL Web Portal used in B&R APROL <4.4-005P may allow an authenticated network-based attacker to access data from the file system.
- CVE-2026-78675HIGHCVSS 7.8EG 8.42026-08-25
GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules fil…
- CVE-2026-94401HIGHCVSS 8.3EG 8.32026-09-21
MISP has a file-handling vulnerability that could let certain authenticated users make the server read files or access internal network services. When importing an XML file, MISP did not properly verify that the uploaded content was actua…
- CVE-2026-54583HIGHCVSS 8.3EG 8.32026-09-17
mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/fetch.c did not consistently reject empty, dot, dot-dot, or slash-containing bundle filenames before composing package download and write paths. Malicious package index dat…
- CVE-2026-15736HIGHCVSS 8.3EG 8.32026-07-14
Snowflake SQLAlchemy versions prior to 1.11.0 contain several security vulnerabilities, including: Improper handling of user-supplied column identifiers in merge operations could allow SQL injection through attacker-controlled input keys. …
- CVE-2026-31939HIGHCVSS 8.3EG 8.32026-04-10
Chamilo LMS is a learning management system. Prior to 1.11.38, there is a path traversal in main/exercise/savescores.php leading to arbitrary file feletion. User input from $_REQUEST['test'] is concatenated directly into filesystem path wi…
- CVE-2026-97662HIGHCVSS 8.2EG 8.22026-10-01
An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 might allow context-dependent threat actors to create, overwrite, or truncate arbitrary files on the host outside the intended wor…
- CVE-2026-79674HIGHCVSS 8.2EG 8.22026-08-25
NLTK versions before 3.10.3 contain a path sandbox bypass vulnerability in corpus-reader constructors that allows attackers to read files outside the intended data root. Attackers can supply arbitrary corpus root paths to LinThesaurusCorpu…
- CVE-2026-45089HIGHCVSS 8.2EG 8.22026-05-27
Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in REST API server mode, the output, output-all, and debug fields in model.Options are JSON-tagged and deserialized directl…
- CVE-2026-40893HIGHCVSS 8.2EG 8.22026-05-14
Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg only checks if the tag is exactly FileName, so System:FileName slips right through and ExifTool happily renames the file. This allows remote attackers to…
- CVE-2026-41693HIGHCVSS 8.2EG 8.22026-05-08
i18next-fs-backend is a backend layer for i18next using in Node.js and for Deno to load translations from the filesystem. Prior to version 2.6.4, i18next-fs-backend substitutes the lng and ns options directly into the configured loadPath /…
- CVE-2026-24708HIGHCVSS 8.2EG 8.22026-02-18
An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend to …
- CVE-2025-62611HIGHCVSS 8.2EG 8.22025-10-22
aiomysql is a library for accessing a MySQL database from the asyncio. Prior to version 0.3.0, the client-side settings are not checked before sending local files to MySQL server, which allows obtaining arbitrary files from the client usin…
- CVE-2025-59292HIGHCVSS 8.2EG 8.22025-10-14
External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally.
- CVE-2025-59291HIGHCVSS 8.2EG 8.22025-10-14
External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally.
- CVE-2025-27147HIGHCVSS 8.2EG 8.22025-03-25
The GLPI Inventory Plugin handles various types of tasks for GLPI agents, including network discovery and inventory (SNMP), software deployment, VMWare ESX host remote inventory, and data collection (files, Windows registry, WMI). Versions…
- CVE-2025-0452HIGHCVSS 8.2EG 8.22025-03-20
eosphoros-ai/DB-GPT version latest is vulnerable to arbitrary file deletion on Windows systems via the '/v1/agent/hub/update' endpoint. The application fails to properly filter the '\' character, which is commonly used as a separator in Wi…
- CVE-2024-8616HIGHCVSS 8.2EG 8.22025-03-20
In h2oai/h2o-3 version 3.46.0, the `/99/Models/{name}/json` endpoint allows for arbitrary file overwrite on the target server. The vulnerability arises from the `exportModelDetails` function in `ModelsHandler.java`, where the user-controll…
- CVE-2023-45588HIGHCVSS 8.2EG 8.22025-03-14
An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installer may allow a local attacker to execute arbitrary code or commands via writing a malicious configu…
- CVE-2024-21545HIGHCVSS 8.2EG 8.22024-09-25
Proxmox Virtual Environment is an open-source server management platform for enterprise virtualization. Insufficient safeguards against malicious API response values allow authenticated attackers with 'Sys.Audit' or 'VM.Monitor' privileges…
- CVE-2024-6255HIGHCVSS 8.2EG 8.22024-07-31
A vulnerability in the JSON file handling of gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to delete any JSON file on the server, including critical configuration files such as `config.json` and `ds_config_chatbot.json`. This…
- CVE-2024-31492HIGHCVSS 8.2EG 8.22024-04-10
An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installer may allow a local attacker to execute arbitrary code or commands via writing a malicious configu…
- CVE-2023-6569HIGHCVSS 8.2EG 8.22023-12-14
External Control of File Name or Path in h2oai/h2o-3
- CVE-2022-43513HIGHCVSS 8.2EG 8.22023-01-10
A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All versions < V6.0 SP9 Upd4), TeleControl Server Basic V3 (All versions < V3.1.2). The affected components allow to rename…
- CVE-2021-22539HIGHCVSS 8.2EG 8.22021-04-16
An attacker can place a crafted JSON config file into the project folder pointing to a custom executable. VScode-bazel allows the workspace path to lint *.bzl files to be set via this config file. As such the attacker is able to execute an…
- CVE-2021-27250HIGHCVSS 6.5EG 8.22021-04-14
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Link DAP-2020 v1.01rc001 Wi-Fi access points. Authentication is not required to exploit this vulnerability. The specific …
- CVE-2026-105865HIGHCVSS 8.1EG 8.12026-10-06
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user who can update or delete uploads stored locally can cause file cleanup to rem…
- CVE-2026-15983HIGHCVSS 8.1EG 8.12026-10-01
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File/Directory Deletion in all versions up to, and including, 6.3.316. This is due to the `super_save_form` AJAX handler performing no capability …
- CVE-2026-103398HIGHCVSS 8.1EG 8.12026-09-30
OpenSave through 2.4.0 fails to properly validate save paths supplied by paired peers in the manifest request handler. Attackers can specify arbitrary directories outside configured save locations to read and write files through manifest a…
- CVE-2026-6205HIGHCVSS 8.1EG 8.12026-09-18
An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write arbitrary files and con…
- CVE-2026-69805HIGHCVSS 8.1EG 8.12026-09-08
External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-85160HIGHCVSS 8.1EG 8.12026-09-03
AVideo through commit c91b5975d contains a cross-site request forgery and path traversal vulnerability in stopLive.php that allows attackers to delete directories by exploiting missing token validation and unsanitized key parameter concate…
- CVE-2026-53580HIGHCVSS 8.1EG 8.12026-08-27
Trilium is an open-source hierarchical note-taking application. In versions prior to 0.104.0, the automatic image-download feature accepts file:// URLs in a note's img tags and reads the referenced local file with no path validation, allow…
- CVE-2026-64679HIGHCVSS 8.1EG 8.12026-08-21
Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. From 0.19.8 until 0.45.0, Atlantis does not consistently validate user-controlled workspace values supplied through accepted reposito…
Map vulnerabilities like CWE-73 to your infrastructure
EchelonGraph correlates every CVE — across CWE-73 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →