CWE-73— External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.— MITRE CWE catalog
714 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-73page 7 of 15
- CVE-2026-25573HIGHCVSS 7.8EG 7.82026-03-10
A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The affected application builds shell commands with caller-provided strings and executes them. An attacker could influence the executed command, potentially re…
- CVE-2026-24287HIGHCVSS 7.8EG 7.82026-03-10
External control of file name or path in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-25636HIGHCVSS 7.8EG 7.82026-02-06
calibre is an e-book manager. In 9.1.0 and earlier, a path traversal vulnerability in Calibre's EPUB conversion allows a malicious EPUB file to corrupt arbitrary existing files writable by the Calibre process. During conversion, Calibre re…
- CVE-2025-62842HIGHCVSS 7.8EG 7.82026-01-02
An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the vulnerability to read or modify files or directories. We hav…
- CVE-2025-59516HIGHCVSS 7.8EG 7.82025-12-09
Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
- CVE-2025-59511HIGHCVSS 7.8EG 7.82025-11-11
External control of file name or path in Windows WLAN Service allows an authorized attacker to elevate privileges locally.
- CVE-2020-36868HIGHCVSS 7.8EG 7.82025-10-30
Nagios XI versions prior to 5.7.3 contain a privilege escalation vulnerability in the getprofile.sh helper script. The script performed profile retrieval and initialization routines using insecure file/command handling and insufficient v…
- CVE-2025-55316HIGHCVSS 7.8EG 7.82025-09-09
External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally.
- CVE-2024-4230HIGHCVSS 7.8EG 7.82024-12-19
External Control of File Name or Path vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic Software for Developers versions 1.00 and later allows a malicious local attacker to execute an arbitra…
- CVE-2024-41183HIGHCVSS 7.8EG 7.82024-10-22
Trend Micro VPN, version 5.8.1012 and below is vulnerable to an arbitrary file overwrite under specific conditions that can lead to elevation of privileges.
- CVE-2024-20366HIGHCVSS 7.8EG 7.82024-05-15
A vulnerability in the Tail-f High Availability Cluster Communications (HCC) function pack of Cisco Crosswork Network Services Orchestrator (NSO) could allow an authenticated, local attacker to elevate privileges to root on an affected dev…
- CVE-2023-5247HIGHCVSS 7.8EG 7.82023-11-30
Malicious Code Execution Vulnerability due to External Control of File Name or Path in multiple Mitsubishi Electric FA Engineering Software Products allows a malicious attacker to execute a malicious code by having legitimate users open a …
- CVE-2023-21566HIGHCVSS 7.8EG 7.82023-02-14
Visual Studio Elevation of Privilege Vulnerability
- CVE-2023-21800HIGHCVSS 7.8EG 7.82023-02-14
Windows Installer Elevation of Privilege Vulnerability
- CVE-2020-6105HIGHCVSS 7.8EG 7.82020-10-15
An exploitable code execution vulnerability exists in the multiple devices functionality of F2fs-Tools F2fs.Fsck 1.13. A specially crafted f2fs filesystem can cause Information overwrite resulting in a code execution. An attacker can provi…
- CVE-2020-1984HIGHCVSS 7.8EG 7.82020-04-08
Secdo tries to execute a script at a hardcoded path if present, which allows a local authenticated user with 'create folders or append data' access to the root of the OS disk (C:\) to gain system privileges if the path does not already exi…
- CVE-2026-73496HIGHCVSS 7.7EG 7.72026-09-14
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a client-controlled file_path through src/m…
- CVE-2026-18127HIGHCVSS 7.7EG 7.72026-08-11
External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage.
- CVE-2026-50158HIGHCVSS 7.7EG 7.72026-07-14
yutu is an AI-powered toolkit for managing and growing YouTube channels. Prior to 0.10.9, the caption-download MCP tool accepts a caller-controlled file parameter through cmd/caption/download.go and passes it to Caption.Download() in pkg/c…
- CVE-2026-42845HIGHCVSS 7.7EG 7.72026-05-11
The form plugin for Grav adds the ability to create and use forms. Prior to 9.1.0 , there is an unauthenticated page-content overwrite via file upload (GHSA-w4rc-p66m-x6qq). Public form uploads now strip path components from the POST-suppl…
- CVE-2025-61879HIGHCVSS 7.7EG 7.72026-02-12
In Infoblox NIOS through 9.0.7, a High-Privileged User Can Trigger an Arbitrary File Write via the Account Creation Mechanism.
- CVE-2026-23529HIGHCVSS 7.7EG 7.72026-01-16
Kafka Connect BigQuery Connector is an implementation of a sink connector from Apache Kafka to Google BigQuery. Prior to 2.11.0, there is an arbitrary file read in Google BigQuery Sink connector. Aiven's Google BigQuery Kafka Connect Sink …
- CVE-2025-30201HIGHCVSS 7.7EG 7.72025-11-21
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.13.0, a vulnerability in Wazuh Agent allows authenticated attackers to force NTLM authentication through malicious UNC paths i…
- CVE-2025-62382HIGHCVSS 7.7EG 7.72025-10-15
Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.2, Frigate's export workflow allows an authenticated operator to nominate any filesystem location as the thumbnail source for a vi…
- CVE-2025-59200HIGHCVSS 7.7EG 7.72025-10-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Data Sharing Service Client allows an unauthorized attacker to perform spoofing locally.
- CVE-2025-54780HIGHCVSS 7.7EG 7.72025-08-05
The glpi-screenshot-plugin allows users to take screenshots or screens recording directly from GLPI. In versions below 2.0.2, authenticated user can use the /ajax/screenshot.php endpoint to leak files from the system or use PHP wrappers. T…
- CVE-2025-3033HIGHCVSS 7.7EG 7.72025-04-01
After selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file could be uploaded. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability was fixed in Fir…
- CVE-2024-33671HIGHCVSS 7.7EG 7.72024-04-26
An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. The Backup Exec Deduplication Multi-threaded Streaming Agent can be leveraged to perform arbitrary file deletion on protected files.
- CVE-2023-28603HIGHCVSS 7.7EG 7.72023-06-13
Zoom VDI client installer prior to 5.14.0 contains an improper access control vulnerability. A malicious user may potentially delete local files without proper permissions.
- CVE-2026-66310HIGHCVSS 7.1EG 7.72026-08-03
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
- CVE-2026-100638HIGHCVSS 7.6EG 7.62026-09-26
SiYuan versions before v3.8.4 contain a path traversal vulnerability in the setNotebookIcon endpoint that allows authenticated administrators to create arbitrary directory trees and write files outside the workspace boundary. Attackers can…
- CVE-2026-100637HIGHCVSS 7.6EG 7.62026-09-26
SiYuan versions before v3.8.4 contain a path traversal vulnerability in the checkoutRepo endpoint that allows authenticated administrators to write JSON files outside the workspace. Attackers can supply a sessionID parameter containing dir…
- CVE-2026-33354HIGHCVSS 6.5EG 7.62026-03-23
WWBN AVideo is an open source video platform. In versions up to and including 26.0, `POST /objects/aVideoEncoder.json.php` accepts a requester-controlled `chunkFile` parameter intended for staged upload chunks. Instead of restricting that …
- CVE-2026-107377HIGHCVSS 7.5EG 7.52026-10-08
datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.81.0, an attacker-controlled Protobuf schema can supply absolute or parent-directory paths captured by WEAK_IMPORT_PATTERN and consumed by _…
- CVE-2026-106219HIGHCVSS 7.5EG 7.52026-10-06
In JetBrains TeamCity before 2026.2.1 missing validation of Git submodule URLs allowed reading local repositories on the server
- CVE-2026-103507HIGHCVSS 7.5EG 7.52026-10-05
Perforce P4 Search prior to 2026.4.2 does not restrict file paths written through its logging configuration interface. An attacker holding the service authentication token can write arbitrary files on the host, potentially leading to code …
- CVE-2026-103591HIGHCVSS 7.5EG 7.52026-09-30
DeepWiki-Open through commit d92819a contains an unauthenticated arbitrary file read vulnerability in the GET /codemap/file endpoint via the repo_url parameter. Attackers can supply a non-URL repo_url value to bypass path containment check…
- CVE-2026-90946HIGHCVSS 7.5EG 7.52026-09-14
DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no containment. Attackers can supply arbitrary directory …
- CVE-2026-85687HIGHCVSS 7.5EG 7.52026-09-04
surya 0.22.1 screenshot server contains an unauthenticated arbitrary file read vulnerability in the /info, /page, and /process routes that accept raw file_path parameters. Attackers can read any image or PDF file on the host by supplying a…
- CVE-2026-85668HIGHCVSS 7.5EG 7.52026-09-04
Xinference (affected commit 4a94832, v3.x) contains an unauthenticated arbitrary-path file read vulnerability in the POST /v1/models/llm/auto-register endpoint, which accepts a caller-supplied model_path parameter without authentication or…
- CVE-2026-84374HIGHCVSS 7.5EG 7.52026-09-01
Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3.1.8 until 3.1.70, in src/Files/Disk.php the Maatwebsite\Excel\Files\Disk::copy() method resolves the caller-controlled $destination supplied through Excel::st…
- CVE-2026-82393HIGHCVSS 7.5EG 7.52026-08-31
pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifest name because pnpm11/resolving/npm-resolver/src/pickPackage.ts rejects slash characters only for u…
- CVE-2026-19084HIGHCVSS 7.5EG 7.52026-08-28
The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a featured image, allowing unauthenticated attackers to read arbitrary files from the server and republish their contents at a publi…
- CVE-2026-16444HIGHCVSS 7.5EG 7.52026-08-26
Improper neutralization of path traversal sequences in TeamViewer Desktop Clients prior Version 15.81.5 allows an authenticated remote session participant to write files to unintended locations on the local file system via file transfer or…
- CVE-2026-19913HIGHCVSS 7.5EG 7.52026-08-25
The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure vulnerability due to improper validation of the ServiceUrl parameter in mwEmbedLoader.php. This parameter is used as the base URL for a backend request and acce…
- CVE-2026-78208HIGHCVSS 7.5EG 7.52026-08-24
exceljs through 4.4.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate file paths. Attackers can supply arbitrary file paths to read any file accessible to the Node.js process and embed it …
- CVE-2026-62385HIGHCVSS 7.5EG 7.52026-08-22
NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files outside the corpus root by supplying unsafe selectors or poisoned index state. Attacke…
- CVE-2026-74884HIGHCVSS 7.5EG 7.52026-08-17
openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path method where the plugin_id parameter is not sanitized before constructing the plugin config directory path. Attackers can declare a malicious…
- CVE-2026-18048HIGHCVSS 7.5EG 7.52026-08-12
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled value used to build a file path in one of its public endpoint actions, and performs no authorisation check on it, allowing unauthenticated att…
- CVE-2026-56452HIGHCVSS 7.5EG 7.52026-07-20
Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. The implementation of receiving files or directories via SCP did not validate filenames in SCP "C" o…
Map vulnerabilities like CWE-73 to your infrastructure
EchelonGraph correlates every CVE — across CWE-73 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →