CWE-73— External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.— MITRE CWE catalog
522 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-73page 9 of 11
- CVE-2026-30903CRITICALCVSS 9.8EG 9.62026-03-11
External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via network access.
- CVE-2026-30905HIGHCVSS 7.8EG 7.82026-05-13
External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11 may allow an authenticated user to conduct an escalation of privilege via local access.
- CVE-2026-30940HIGHCVSS 7.2EG 7.22026-03-31
baserCMS is a website development framework. Prior to version 5.2.3, a path traversal vulnerability exists in the theme file management API (/baser/api/admin/bc-theme-file/theme_files/add.json) that allows arbitrary file write. An authenti…
- CVE-2026-31939HIGHCVSS 8.3EG 8.32026-04-10
Chamilo LMS is a learning management system. Prior to 1.11.38, there is a path traversal in main/exercise/savescores.php leading to arbitrary file feletion. User input from $_REQUEST['test'] is concatenated directly into filesystem path wi…
- CVE-2026-32204HIGHCVSS 7.8EG 7.82026-05-12
External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
- CVE-2026-32749CRITICALCVSS 9.1EG 9.12026-03-19
SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importSY and POST /api/import/importZipMd write uploaded archives to a path derived from the multipart filename field without sanitization, all…
- CVE-2026-32949HIGHCVSS 7.5EG 7.52026-03-20
SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a Server-Side Request Forgery (SSRF) vulnerability that allows an attacker to retrieve arbitrary system and application fil…
- CVE-2026-33027MEDIUMCVSS 6.5EG 6.52026-03-30
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui configuration improperly handles URL-encoded traversal sequences. When specially crafted paths are supplied, the backend resolves them to the b…
- CVE-2026-33309CRITICALCVSS 9.9EG 9.92026-03-19
Langflow is a tool for building and deploying AI-powered agents and workflows. Versions 1.2.0 through 1.8.1 have a bypass of the patch for CVE-2025-68478 (External Control of File Name), leading to the root architectural issue within `Loca…
- CVE-2026-33329HIGHCVSS 8.1EG 8.12026-03-24
FileRise is a self-hosted web file manager / WebDAV server. From version 1.0.1 to before version 3.10.0, the resumableIdentifier parameter in the Resumable.js chunked upload handler (UploadModel::handleUpload()) is concatenated directly in…
- CVE-2026-33354HIGHCVSS 6.5EG 7.62026-03-23
WWBN AVideo is an open source video platform. In versions up to and including 26.0, `POST /objects/aVideoEncoder.json.php` accepts a requester-controlled `chunkFile` parameter intended for staged upload chunks. Instead of restricting that …
- CVE-2026-33476HIGHCVSS 7.5EG 7.52026-03-20
SiYuan is a personal knowledge management system. Prior to version 3.6.2, the Siyuan kernel exposes an unauthenticated file-serving endpoint under `/appearance/*filepath.` Due to improper path sanitization, attackers can perform directory …
- CVE-2026-33645HIGHCVSS 8.1EG 8.12026-03-26
Fireshare facilitates self-hosted media and link sharing. In version 1.5.1, an authenticated path traversal vulnerability in Fireshare’s chunked upload endpoint allows an attacker to write arbitrary files outside the intended upload dire…
- CVE-2026-33949HIGHCVSS 8.1EG 8.12026-04-01
Tina is a headless content management system. Prior to version 2.2.2, a path traversal vulnerability in @tinacms/graphql allows unauthenticated users to write and overwrite arbitrary files within the project root. This is achieved by manip…
- CVE-2026-33989MEDIUMCVSS 6.5EG 6.52026-03-27
Mobile Next is an MCP server for mobile development and automation. Prior to version 0.0.49, the `@mobilenext/mobile-mcp` server contains a Path Traversal vulnerability in the `mobile_save_screenshot` and `mobile_start_screen_recording` to…
- CVE-2026-34030MEDIUMCVSS 6.9EG 6.92026-06-15
The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, does not sufficiently validate the branch code when a new branch is created. The branch code is later used in multiple application functions, including filesystem path…
- CVE-2026-34522HIGHCVSS 8.1EG 8.12026-04-02
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to version 1.17.0, a path traversal vulnerability …
- CVE-2026-34783HIGHCVSS 8.1EG 8.12026-04-06
Ferret is a declarative system for working with web data. Prior to 2.0.0-alpha.4, a path traversal vulnerability in Ferret's IO::FS::WRITE standard library function allows a malicious website to write arbitrary files to the filesystem of t…
- CVE-2026-35032HIGHCVSS 8.1EG 8.12026-04-14
Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the LiveTV M3U tuner endpoint (POST /LiveTv/TunerHosts), where the tuner URL is not validated, allowing local file read via non…
- CVE-2026-35076HIGHCVSS 8.1EG 8.12026-06-03
The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
- CVE-2026-35077HIGHCVSS 8.1EG 8.12026-06-03
The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
- CVE-2026-35078HIGHCVSS 8.1EG 8.12026-06-03
The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
- CVE-2026-35079HIGHCVSS 8.1EG 8.12026-06-03
The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
- CVE-2026-35080HIGHCVSS 8.1EG 8.12026-06-03
The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
- CVE-2026-35174HIGHCVSS 7.2EG 7.22026-04-06
Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, a path traversal vulnerability exists in the administration console that allows an administrator or a user with Change Settings permission to change the uploads path to …
- CVE-2026-35465HIGHCVSS 7.5EG 7.52026-04-18
SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. In versions 0.17.4 and below, a compromised SecureDrop Server can achieve code execution on the C…
- CVE-2026-35593MEDIUMCVSS 6.8EG 6.82026-05-20
Trilium Notes is an open-source, cross-platform hierarchical note taking application for building large personal knowledge bases. Versions 0.102.1 and prior are vulnerable to Local File Inclusion, allowing an authenticated attacker to read…
- CVE-2026-3602MEDIUMCVSS 5.5EG 5.52026-06-30
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 is vulnerable to SQL injection. A remote attacker could socially engineer a user into accident…
- CVE-2026-3892HIGHCVSS 8.1EG 8.12026-05-14
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.4.107. This is due to insufficient file path validation in the become-dealer l…
- CVE-2026-39006CRITICALCVSS 9.8EG 9.82026-06-15
An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component.
- CVE-2026-39377MEDIUMCVSS 6.5EG 6.52026-04-21
The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions 6.5 through 7.17.0 allow arbitrary file writes to locations outside the intended output directory when processing note…
- CVE-2026-39378MEDIUMCVSS 6.5EG 6.52026-04-21
The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. In versions 6.5 through 7.17.0, when `HTMLExporter.embed_images=True`, nbconvert's markdown renderer allows arbitrary file read…
- CVE-2026-39907CRITICALCVSS 10.0EG 10.02026-04-14
Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on TCP port 1208 that accepts unsanitized file paths in the ReadLicense action's LFName parameter, allowing remote attacke…
- CVE-2026-40086MEDIUMCVSS 5.3EG 5.32026-04-10
Rembg is a tool to remove images background. Prior to 2.0.75, a path traversal vulnerability in the rembg HTTP server allows unauthenticated remote attackers to read arbitrary files from the server's filesystem. By sending a crafted reques…
- CVE-2026-40342CRITICALCVSS 9.9EG 9.92026-04-17
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-supplied engine name into a filesystem path without filtering path separa…
- CVE-2026-40370HIGHCVSS 8.8EG 8.82026-05-12
External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-40421MEDIUMCVSS 4.3EG 4.32026-05-12
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- CVE-2026-40605MEDIUMCVSS 5.7EG 5.72026-06-04
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.1, a path traversal vulnerability in the cache deletion endpoint allows authenticated API access to delete directories outside the configu…
- CVE-2026-40893HIGHCVSS 8.2EG 8.22026-05-14
Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg only checks if the tag is exactly FileName, so System:FileName slips right through and ExifTool happily renames the file. This allows remote attackers to…
- CVE-2026-41088HIGHCVSS 7.8EG 7.82026-05-12
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- CVE-2026-41107HIGHCVSS 7.4EG 7.42026-05-12
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
- CVE-2026-41177MEDIUMCVSS 5.5EG 5.52026-04-22
Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the Squidex Restore API is vulnerable to Blind Server-Side Request Forgery (SSRF). The application fails to validate the URI …
- CVE-2026-4132HIGHCVSS 7.2EG 7.22026-04-22
The HTTP Headers plugin for WordPress is vulnerable to External Control of File Name or Path leading to Remote Code Execution in all versions up to and including 1.19.2. This is due to insufficient validation of the file path stored in the…
- CVE-2026-41389MEDIUMCVSS 5.8EG 5.82026-04-20
OpenClaw versions 2026.4.7 before 2026.4.15 fail to enforce local-root containment on tool-result media paths, allowing arbitrary local and UNC file access. Attackers can craft malicious tool-result media references to trigger host-side fi…
- CVE-2026-41412MEDIUMCVSS 4.9EG 4.92026-06-02
alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5-2606, the alf.io extension sandbox injects a fully-functional HTTP client (`simpleHttpClient`) into every exte…
- CVE-2026-41693HIGHCVSS 8.2EG 8.22026-05-08
i18next-fs-backend is a backend layer for i18next using in Node.js and for Deno to load translations from the filesystem. Prior to version 2.6.4, i18next-fs-backend substitutes the lng and ns options directly into the configured loadPath /…
- CVE-2026-42424MEDIUMCVSS 5.7EG 5.72026-04-28
OpenClaw before 2026.4.8 treats shared reply MEDIA paths as trusted, allowing crafted references to trigger cross-channel local file exfiltration. Attackers can exploit this by crafting malicious shared reply MEDIA references to cause anot…
- CVE-2026-42593MEDIUMCVSS 5.3EG 5.32026-05-14
Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, pdfengines/merge, pdfengines/split, libreoffice/convert, chromium/convert/url, chromium/convert/html, and chromium/convert/markdown accept stampSource=pdf + stampE…
- CVE-2026-42597MEDIUMCVSS 5.9EG 5.92026-05-14
Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the /forms/chromium/convert/url and /forms/chromium/screenshot/url routes accept url=file:///tmp/... from anonymous callers. The default Chromium deny-list intenti…
- CVE-2026-42845HIGHCVSS 7.7EG 7.72026-05-11
The form plugin for Grav adds the ability to create and use forms. Prior to 9.1.0 , there is an unauthenticated page-content overwrite via file upload (GHSA-w4rc-p66m-x6qq). Public form uploads now strip path components from the POST-suppl…
Map vulnerabilities like CWE-73 to your infrastructure
EchelonGraph correlates every CVE — across CWE-73 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →