CWE-646: Reliance on File Name or Extension of Externally-Supplied File
The product allows a file to be uploaded, but it relies on the file name or extension of the file to determine the appropriate behaviors. This could be used by attackers to cause the file to be misclassified and processed in a dangerous fashion.
10 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-52052 — Stream Target Remote Code Execution in Wowza Streaming Engine
- CVE-2025-58449 — Maho Vulnerable to Authenticated Remote Code Execution via File Upload
- CVE-2026-45315 — Open WebUI: Stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions
- CVE-2025-30662 — Zoom Workplace VDI Plugin macOS Universal Installer - Symlink Following
- CVE-2024-38432 — Matrix – Tafnit v8 CWE-646: Reliance on File Name or Extension of Externally-Supplied File
- CVE-2025-1889 — picklescan - Security scanning bypass via non-standard file extensions
- CVE-2025-41720 — Sauter: Arbitrary File Upload
- CVE-2026-20172 — Cisco Enterprise Chat and Email Lite Agent File Upload Vulnerability
Recently published
- CVE-2026-45315 — Open WebUI: Stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions
- CVE-2026-20172 — Cisco Enterprise Chat and Email Lite Agent File Upload Vulnerability
- CVE-2025-30662 — Zoom Workplace VDI Plugin macOS Universal Installer - Symlink Following
- CVE-2025-41720 — Sauter: Arbitrary File Upload
- CVE-2025-58449 — Maho Vulnerable to Authenticated Remote Code Execution via File Upload
- CVE-2025-1889 — picklescan - Security scanning bypass via non-standard file extensions
- CVE-2024-52052 — Stream Target Remote Code Execution in Wowza Streaming Engine
- CVE-2024-38432 — Matrix – Tafnit v8 CWE-646: Reliance on File Name or Extension of Externally-Supplied File