CWE-73— External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.— MITRE CWE catalog
494 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-73page 10 of 10
- CVE-2026-50006CRITICALCVSS 9.1EG 9.12026-07-14
Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server Mode ## Summary Anyquery's `server` mode does not disable or restrict native SQLite disk manipulation commands…
- CVE-2026-50148CRITICALCVSS 10.0EG 10.02026-07-15
Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user with permission to add or edit a database connection can achi…
- CVE-2026-50162MEDIUMCVSS 6.9EG 6.92026-07-01
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, resolveWritePath() in content/file/file.go uses a lexical filepath.Rel check for workingDir and does not account for symlink traversal, so when AllowPathTraversalOnWrite=f…
- CVE-2026-50462HIGHCVSS 7.8EG 7.82026-07-14
External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- CVE-2026-5053HIGHCVSS 7.1EG 7.12026-04-11
NoMachine External Control of File Path Arbitrary File Deletion Vulnerability. This vulnerability allows local attackers to delete arbitrary files on affected installations of NoMachine. An attacker must first obtain the ability to execute…
- CVE-2026-5054HIGHCVSS 7.8EG 7.82026-04-11
NoMachine External Control of File Path Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine. An attacker must first obtain the ability to execute…
- CVE-2026-5210HIGHCVSS 7.3EG 7.32026-03-31
A vulnerability was detected in SourceCodester Leave Application System 1.0. This affects an unknown part. Performing a manipulation of the argument page results in file inclusion. Remote exploitation of the attack is possible. The exploit…
- CVE-2026-53449MEDIUMCVSS 6.0EG 6.02026-07-10
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, the psd print sessions dump CLI command in coturn takes a filename argument and directly passes it to fopen with no path validation. An authenticated adm…
- CVE-2026-53632MEDIUMCVSS 5.5EG 5.52026-06-15
launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a UNC path is opened, Windows automatically attemp…
- CVE-2026-53648MEDIUMCVSS 5.1EG 5.12026-07-06
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.1, downloadable product files are stored using a deterministic filename-derived path. When an administrator uploads a file for a downloadable pro…
- CVE-2026-53915HIGHCVSS 8.8EG 8.82026-06-19
In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration
- CVE-2026-54108MEDIUMCVSS 6.5EG 6.52026-07-14
External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-54629HIGHCVSS 7.5EG 7.52026-07-14
Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode ## Summary Anyquery's `server` mode lacks input sanitization and access control over its built-in SQLite virtual table modules (e.g., `csv_reader…
- CVE-2026-55002HIGHCVSS 7.8EG 7.82026-07-14
External control of file name or path in SQL Server allows an authorized attacker to elevate privileges locally.
- CVE-2026-55477HIGHCVSS 7.2EG 7.22026-06-25
3X-UI is a web control panel for managing Xray-core servers. Prior to 3.3.1, an authenticated administrator can abuse the database import functionality to achieve arbitrary file write on the host by modifying Xray configuration values stor…
- CVE-2026-55628MEDIUMCVSS 5.5EG 5.52026-07-01
In versions prior to 7.1.2-26he, the `-concatenate` operation is missing policy checks, potentially resulting in both reading and writing to paths disallowed by the security policy. This issue has been fixed in version 7.1.2-26.
- CVE-2026-55699MEDIUMCVSS 6.5EG 6.52026-06-25
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, Manifest bin object keys such as "", ".", and ".." passed pnpm's bin-name guard. When a malicious package was installed globally, later global remove, update, or add-replacement flows…
- CVE-2026-55700HIGHCVSS 7.1EG 7.12026-06-25
pnpm is a package manager. From 11.3.0 until 11.5.3, `pnpm stage download` derived a local filename from registry-controlled package name and version fields. A crafted manifest could escape the selected download directory and overwrite ano…
- CVE-2026-56452HIGHCVSS 7.5EG 7.52026-07-20
Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. The implementation of receiving files or directories via SCP did not validate filenames in SCP "C" o…
- CVE-2026-57898CRITICALCVSS 9.0EG 9.02026-07-14
In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauthenticated arbitrary file write through the AAS thumbnail API. The AAS thumbnail upload…
- CVE-2026-5809HIGHCVSS 7.1EG 7.12026-04-11
The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.2. This is due to a two-step logic flaw: the topic_add() and topic_edit() action handlers accept arbitrary user-supplied dat…
- CVE-2026-58192HIGHCVSS 8.6EG 8.62026-07-08
Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 1.1.6, the Appium storage plugin exposes POST /storage/delete, whose handler passes the user-supplied name value di…
- CVE-2026-5821HIGHCVSS 8.1EG 8.12026-07-02
The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to and including 1.7.4. This is due to insufficient path validation in the Image_Backup::remove() function where backup file paths stored in p…
- CVE-2026-58293HIGHCVSS 8.1EG 8.12026-07-03
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- CVE-2026-58484HIGHCVSS 7.1EG 7.12026-07-20
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.listBackups()` reads each backup's `_manifest.json` and trusts the manifest's `path` field. `EnvironmentManager.pruneBackups()` later…
- CVE-2026-59194HIGHCVSS 7.1EG 7.12026-07-06
pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patch entry could resolve outside the configured patches directory and cause pnpm patch-remove to delete an arbitrary reachable file. This vulnerability is fixed in 10.34.4 …
- CVE-2026-59196HIGHCVSS 7.1EG 7.12026-07-06
pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockfile alias could be joined directly under a hoisted node_modules directory. Traversal aliases could escape that directory, while reserved aliases such as .bin or .pnpm c…
- CVE-2026-59793HIGHCVSS 8.8EG 8.82026-07-10
In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration
- CVE-2026-59807MEDIUMCVSS 6.8EG 6.82026-07-08
Composio SDK before 0.2.32-beta.283 contains a path validation bypass vulnerability that allows attackers to read and exfiltrate sensitive files by exploiting a missing assertSafeFileUploadPath check in the readFileFromDisk function within…
- CVE-2026-59819MEDIUMCVSS 4.9EG 4.92026-07-08
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.10-stable, LiteLLM's /health/test_connection endpoint resolved request-supplied environment and OIDC file references in litellm_params, all…
- CVE-2026-6070CRITICALCVSS 9.1EG 9.12026-07-01
The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions up to and including 4.0.1. This is due to insufficient path validation in the remove() method of the JBusinessDirectoryContr…
- CVE-2026-6101HIGHCVSS 7.5EG 7.52026-07-07
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Arbitrary File Write in versions up to and including 1.1.12. This is due to unsafe ZIP file extraction in the ampforwp_save_local_font() function combined wi…
- CVE-2026-61462HIGHCVSS 8.6EG 8.62026-07-13
mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can supply crafted job_id values like ../../../user to esc…
- CVE-2026-61873HIGHCVSS 8.1EG 8.12026-07-15
Grav before 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process.save.filename parameter, which is validated against path traversal before Twig processing but never re-validated after rendering. Attackers can s…
- CVE-2026-65896HIGHCVSS 7.1EG 7.12026-07-23
Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in the POST /pages/{route}/move endpoint. PagesController::move() sanitizes the slug only with ltrim($body['slug'], '.'), wh…
- CVE-2026-7633MEDIUMCVSS 6.5EG 6.52026-05-02
A vulnerability was identified in Totolink N300RH 6.1c.1353_B20190305. This impacts the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument FileName leads to file inclusion. The attack may be perfo…
- CVE-2026-8043CRITICALCVSS 9.6EG 9.62026-05-12
External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to information disclosure and possible clie…
- CVE-2026-8095HIGHCVSS 8.1EG 8.12026-06-27
The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. This is due to a case-sensitive bypass of the wpfm_dir_path parameter sanitization in the wp…
- CVE-2026-8118MEDIUMCVSS 6.5EG 6.52026-06-19
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Arbitrary File Read in versions 1.7.1058 through 1.7.1059. This is due to the wpr_get_csv_handle() helper (introduced in versio…
- CVE-2026-8450CRITICALCVSS 9.1EG 9.12026-05-27
HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subproce…
- CVE-2026-8920HIGHCVSS 8.5EG 8.52026-07-15
Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary file …
- CVE-2026-8921HIGHCVSS 8.5EG 8.52026-07-03
External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary code with SYSTEM privileges via a tampered IPC message. Refer to the ' Security Update for ASUS Business Manager ' secti…
- CVE-2026-9559CRITICALCVSS 9.9EG 9.92026-05-29
A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the validation logic allows file paths to escape the intended temporary directories. An…
- CVE-2026-9587HIGHCVSS 7.1EG 7.12026-07-17
An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file functionality accepts user-controlled input through the sound_path parameter and fails to properly validate file paths …
Map vulnerabilities like CWE-73 to your infrastructure
EchelonGraph correlates every CVE — across CWE-73 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →