CWE-73— External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.— MITRE CWE catalog
662 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-73page 12 of 14
- CVE-2026-55699MEDIUMCVSS 6.5EG 6.52026-06-25
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, Manifest bin object keys such as "", ".", and ".." passed pnpm's bin-name guard. When a malicious package was installed globally, later global remove, update, or add-replacement flows…
- CVE-2026-55700HIGHCVSS 7.1EG 7.12026-06-25
pnpm is a package manager. From 11.3.0 until 11.5.3, `pnpm stage download` derived a local filename from registry-controlled package name and version fields. A crafted manifest could escape the selected download directory and overwrite ano…
- CVE-2026-56390MEDIUMCVSS 6.3EG 6.32026-07-29
GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %header allow specifying file paths, which are accepted without restriction and override caller‑supplied output options. When processing…
- CVE-2026-56452HIGHCVSS 7.5EG 7.52026-07-20
Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. The implementation of receiving files or directories via SCP did not validate filenames in SCP "C" o…
- CVE-2026-56705CRITICALCVSS 9.8EG 9.82026-08-25
Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP c…
- CVE-2026-57898CRITICALCVSS 9.0EG 9.02026-07-14
In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauthenticated arbitrary file write through the AAS thumbnail API. The AAS thumbnail upload…
- CVE-2026-57916MEDIUMCVSS 4.6EG 4.62026-07-27
proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can prepare arbitrary certificate with CPS URI pointing to a local executable file or any URL, sign a document with it, and send it t…
- CVE-2026-5809HIGHCVSS 7.1EG 7.12026-04-11
The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.2. This is due to a two-step logic flaw: the topic_add() and topic_edit() action handlers accept arbitrary user-supplied dat…
- CVE-2026-58192CRITICALCVSS 10.0EG 10.02026-07-08
Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 1.1.6, the Appium storage plugin exposes POST /storage/delete, whose handler passes the user-supplied name value di…
- CVE-2026-5821HIGHCVSS 8.1EG 8.12026-07-02
The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to and including 1.7.4. This is due to insufficient path validation in the Image_Backup::remove() function where backup file paths stored in p…
- CVE-2026-58293HIGHCVSS 8.1EG 8.12026-07-03
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- CVE-2026-58484HIGHCVSS 7.1EG 7.12026-07-20
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.listBackups()` reads each backup's `_manifest.json` and trusts the manifest's `path` field. `EnvironmentManager.pruneBackups()` later…
- CVE-2026-59194HIGHCVSS 7.1EG 7.12026-07-06
pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patch entry could resolve outside the configured patches directory and cause pnpm patch-remove to delete an arbitrary reachable file. This vulnerability is fixed in 10.34.4 …
- CVE-2026-59196HIGHCVSS 7.1EG 7.12026-07-06
pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockfile alias could be joined directly under a hoisted node_modules directory. Traversal aliases could escape that directory, while reserved aliases such as .bin or .pnpm c…
- CVE-2026-59682CRITICALCVSS 9.1EG 9.12026-08-26
Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB. This issue affects OpenRGB through 1.0rc3.
- CVE-2026-59683CRITICALCVSS 9.8EG 9.82026-08-26
The OpenRGB network protocol allows to write attacker controlled strings into arbitrary file system paths (extension of CVE-2026-59682). This allows either a full system compromise from local or remote (if the daemon is running as root) or…
- CVE-2026-59793HIGHCVSS 8.8EG 8.82026-07-10
In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration
- CVE-2026-59807MEDIUMCVSS 6.8EG 6.82026-07-08
Composio SDK before 0.2.32-beta.283 contains a path validation bypass vulnerability that allows attackers to read and exfiltrate sensitive files by exploiting a missing assertSafeFileUploadPath check in the readFileFromDisk function within…
- CVE-2026-59819MEDIUMCVSS 4.9EG 4.92026-07-08
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.10-stable, LiteLLM's /health/test_connection endpoint resolved request-supplied environment and OIDC file references in litellm_params, all…
- CVE-2026-60009HIGHCVSS 8.8EG 8.82026-08-05
In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deployment. The handler takes an attacker-supplied absolute path from the multipart `uri` field and…
- CVE-2026-6070CRITICALCVSS 9.1EG 9.12026-07-01
The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions up to and including 4.0.1. This is due to insufficient path validation in the remove() method of the JBusinessDirectoryContr…
- CVE-2026-6101HIGHCVSS 7.5EG 7.52026-07-07
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Arbitrary File Write in versions up to and including 1.1.12. This is due to unsafe ZIP file extraction in the ampforwp_save_local_font() function combined wi…
- CVE-2026-61462HIGHCVSS 8.6EG 8.62026-07-13
mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can supply crafted job_id values like ../../../user to esc…
- CVE-2026-61873HIGHCVSS 8.1EG 8.12026-07-15
Grav before 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process.save.filename parameter, which is validated against path traversal before Twig processing but never re-validated after rendering. Attackers can s…
- CVE-2026-6205HIGHCVSS 8.1EG 8.12026-09-18
An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write arbitrary files and con…
- CVE-2026-62385HIGHCVSS 7.5EG 7.52026-08-22
NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files outside the corpus root by supplying unsafe selectors or poisoned index state. Attacke…
- CVE-2026-62804HIGHCVSS 7.8EG 7.82026-09-08
External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2026-62865HIGHCVSS 8.7EG 8.72026-08-25
Typebot is an open-source chatbot builder. In self-hosted versions prior to 3.18.0, the server-side Send Email integration block allows arbitrary reading of local files on the server. The block builds Nodemailer attachments from a typebot …
- CVE-2026-63225MEDIUMCVSS 4.4EG 4.42026-09-16
Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to @redocly/cli 2.33.2, the split command constructs output paths under --outDir from untrusted OpenAPI or AsyncAPI component names and x-codeSamples …
- CVE-2026-63343CRITICALCVSS 9.9EG 9.92026-08-21
Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path allows an authenticated Incus user to read or overwrite any file on …
- CVE-2026-64679HIGHCVSS 8.1EG 8.12026-08-21
Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. From 0.19.8 until 0.45.0, Atlantis does not consistently validate user-controlled workspace values supplied through accepted reposito…
- CVE-2026-64816MEDIUMCVSS 6.5EG 6.52026-07-30
RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to File::open() in lut_processing.rs. On Windows, a UNC path in lutPath causes an outbound SMB connection to an attacker-controlled host, leaking t…
- CVE-2026-65802HIGHCVSS 7.4EG 7.42026-08-03
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
- CVE-2026-65896HIGHCVSS 7.1EG 7.12026-07-23
Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in the POST /pages/{route}/move endpoint. PagesController::move() sanitizes the slug only with ltrim($body['slug'], '.'), wh…
- CVE-2026-65939MEDIUMCVSS 6.8EG 6.82026-08-12
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.
- CVE-2026-65941HIGHCVSS 8.8EG 8.82026-08-12
In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.
- CVE-2026-66302CRITICALCVSS 9.8EG 9.82026-09-08
External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.
- CVE-2026-66310HIGHCVSS 7.1EG 7.72026-08-03
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
- CVE-2026-66324MEDIUMCVSS 6.5EG 6.52026-08-28
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-67429CRITICALCVSS 10.0EG 10.02026-07-29
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_with_env_config and its FLYTO_SANDBOX_DIR …
- CVE-2026-67920HIGHCVSS 8.8EG 8.82026-08-18
An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.halo.app.migration.impl.MigrationServiceImpl.restoreWorkdir(), and org.springframework.util.FileSystemUtils.copyRecursively() components
- CVE-2026-69355HIGHCVSS 8.8EG 8.82026-09-08
External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
- CVE-2026-69383HIGHCVSS 7.0EG 7.02026-09-08
External control of file name or path in Windows Shell allows an authorized attacker to elevate privileges locally.
- CVE-2026-69805HIGHCVSS 7.5EG 7.52026-09-08
External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-72742HIGHCVSS 8.6EG 8.62026-08-11
DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field adapters that allows attackers with influence over language model outputs to read arbitrary local files by injecting a filesystem path into the url…
- CVE-2026-72841CRITICALCVSS 9.9EG 9.92026-08-13
luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory. Attackers can upload malicious pa…
- CVE-2026-72842CRITICALCVSS 9.9EG 9.92026-08-13
luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit path traversal via `/.%2E…
- CVE-2026-73171HIGHCVSS 8.6EG 8.62026-09-16
Nozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in the backup-restore workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to overwrite ar…
- CVE-2026-73496HIGHCVSS 7.7EG 7.72026-09-14
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a client-controlled file_path through src/m…
- CVE-2026-73619MEDIUMCVSS 6.5EG 6.52026-08-13
GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the fil…
Map vulnerabilities like CWE-73 to your infrastructure
EchelonGraph correlates every CVE — across CWE-73 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →