CWE-73: External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.
586 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-54945 — SUNNET Corporate Training Management System - External Control of File Name or Path
- CVE-2025-64712 — Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write
- CVE-2025-6237 — Path Traversal and Arbitrary File Deletion in invoke-ai/invokeai
- CVE-2025-0851 — Path traversal issue in Deep Java Library
- CVE-2024-46909 — WhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution Vulnerability
- CVE-2026-30903 — External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauth
- CVE-2026-30240 — Budibase PWA ZIP Upload Path Traversal Allows Reading Arbitrary Server Files Including All Environment Secrets
- CVE-2026-22783 — Iris Allows Arbitrary File Deletion via Mass Assignment in Datastore File Management
- CVE-2025-53912 — An arbitrary file read vulnerability exists in the encapsulatedDoc functionality of MedDream PACS Premium 7.3.6.870. A s
- CVE-2024-1244 — Remote code execution and local privilege escalation due to UNC access and NetNTLMv2 hash theft
- CVE-2024-1243 — Remote code execution and local privilege escalation in Wazuh Windows agent via NetNTLMv2 hash theft
- CVE-2025-0111 — PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface
- CVE-2025-64486 — calibre is vulnerable to arbitrary code execution when opening FB2 files
- CVE-2025-55746 — Directus allows unauthenticated file upload and file modification due to lacking input sanitization
- CVE-2025-66257 — Unauthenticated Arbitrary File Deletion (patch_contents.php)
- CVE-2026-27825 — MCP Atlassian has an arbitrary file write leading to arbitrary code execution via unconstrained download_path in confluence_download_attachment
- CVE-2026-27211 — Cloud Hypervisor: Host File Exfiltration via QCOW Backing File Abuse
- CVE-2025-58762 — Tautulli vulnerable to Authenticated Remote Code Execution via write primitive and `Script` notification agent
- CVE-2025-33117 — IBM QRadar SIEM command execution
- CVE-2025-2409 — Admin Authorized System File corruption
Recently published
- CVE-2026-86751 — Snipe-IT before 8.7.0 Arbitrary File Read and SSRF via Markdown
- CVE-2026-86741 — Snipe-IT before 8.7.0 Arbitrary File Read and SSRF via Category EULA
- CVE-2026-79692 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-87815 — SiYuan before v3.8.2 Path Traversal via removeRiffDeck
- CVE-2026-53581 — ntp: write path traversal
- CVE-2026-86995 — n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
- CVE-2026-78620 — Improper Path Validation in Okta Access Gateway Kerberos Configuration Handling
- CVE-2026-81830 — The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted c
- CVE-2026-86189 — WWBN AVideo Unauthenticated Path Traversal via notify.ffmpeg.json.php
- CVE-2026-80119 — PassMark PerformanceTest, BurnInTest, and OSForensics Physical Memory Disclosure via DirectIo64.sys IOCTL
- CVE-2026-80118 — PassMark PerformanceTest, BurnInTest, and OSForensics Kernel Null Pointer Dereference via DirectIo64.sys IOCTL
- CVE-2026-85687 — surya 0.22.1 Unauthenticated Arbitrary File Read via screenshot server
- CVE-2026-85684 — marker through 2.0.0 Path Traversal via upload filename
- CVE-2026-85668 — Xinference 3.3.0 Unauthenticated Arbitrary-Path File Read via /v1/models/llm/auto-register
- CVE-2026-85603 — Grav Admin Plugin Path Traversal via Save As Language Code
- CVE-2026-75602 — OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool
- CVE-2026-85176 — DbGate through 7.2.6 Arbitrary File Read and Write via file:// jslid
- CVE-2026-85160 — AVideo through c91b5975d CSRF and Path Traversal via stopLive.php
- CVE-2026-84478 — WWBN AVideo Unauthenticated Arbitrary Log File Deletion
- CVE-2026-84374 — Laravel Excel writes exports outside the configured filesystem disk when given a caller-controlled path
More specific weaknesses
- CWE-114 — Process Control