VYPR

CWE-426

Untrusted Search Path

BaseStableLikelihood: High

Description

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-38

CVEs mapped to this weakness (691)

page 23 of 35
  • CVE-2026-78574HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.00

    The Okta Hyperdrive Integration plugin resolves a required assembly using a registry path within the current user's hive without integrity verification. The referenced path is loaded via Assembly.LoadFrom without signature validation, resulting in an unverified assembly…

  • CVE-2026-41294HigApr 21, 2026
    risk 0.49cvss 8.6epss 0.00

    OpenClaw before 2026.3.28 loads the current working directory .env file before trusted state-dir configuration, allowing environment variable injection. Attackers can place a malicious .env file in a repository or workspace to override runtime configuration and…

  • CVE-2025-12819HigDec 3, 2025
    risk 0.49cvss 7.5epss 0.00

    Untrusted search path in auth_query connection handler in PgBouncer before 1.25.1 allows an unauthenticated attacker to execute arbitrary SQL during authentication via a malicious search_path parameter in the StartupMessage.

  • CVE-2025-30399HigJun 13, 2025
    risk 0.49cvss 7.5epss 0.01

    Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.

  • CVE-2025-1756HigFeb 27, 2025
    risk 0.49cvss 7.5epss 0.00

    mongosh may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privilege, when a crafted file is stored in C:\node_modules\. This issue affects mongosh prior to 2.3.0

  • CVE-2025-1755HigFeb 27, 2025
    risk 0.49cvss 7.5epss 0.00

    MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in C:\node_modules\. This issue affects MongoDB Compass prior to 1.42.1

  • CVE-2024-23304HigFeb 6, 2024
    risk 0.49cvss 7.5epss 0.01

    Cybozu KUNAI for Android 3.0.20 to 3.0.21 allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition by performing certain operations.

  • CVE-2023-29790HigMay 12, 2023
    risk 0.49cvss 7.5epss 0.01

    kodbox 1.2.x through 1.3.7 has a Sensitive Information Leakage issue.

  • CVE-2016-10837HigAug 1, 2019
    risk 0.49cvss 7.5epss 0.02

    cPanel before 11.54.0.4 allows arbitrary code execution because of an unsafe @INC path (SEC-46).

  • CVE-2018-10959HigApr 17, 2019
    risk 0.49cvss 7.5epss 0.02

    Avecto Defendpoint 4 prior to 4.4 SR6 and 5 prior to 5.1 SR1 has an Untrusted Search Path vulnerability, exploitable by modifying environment variables to trigger automatic elevation of an attacker's process launch.

  • CVE-2016-0018HigJan 13, 2016
    risk 0.49cvss 7.3epss 0.13

    Microsoft Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 R2, and Windows 10 Gold and 1511 mishandle DLL loading, which allows local users to gain privileges via a crafted application, aka "DLL Loading Remote Code Execution Vulnerability."

  • CVE-2026-84226HigSep 7, 2026
    risk 0.48cvss —epss 0.00

    OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to perform a binary planting attack during network configuration steps

  • CVE-2026-82862HigAug 31, 2026
    risk 0.48cvss 8.4epss 0.00

    Hulumi versions before v1.3.2 resolve the threat-model helper script from an unsafe root, allowing workspace files to shadow the intended helper script. Attackers can place malicious files in the workspace to execute arbitrary code during local skill execution.

  • CVE-2026-47211HigAug 3, 2026
    risk 0.48cvss —epss 0.00

    Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. In versions prior to 0.39.0, if a user clones a malicious repository and runs Ouroboros commands within that directory, it can lead to…

  • CVE-2026-48287HigJul 14, 2026
    risk 0.48cvss 7.4epss 0.00

    CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in…

  • CVE-2026-40287HigApr 14, 2026
    risk 0.48cvss 8.4epss 0.00

    PraisonAI is a multi-agent teams system. Versions 4.5.138 and below are vulnerable to arbitrary code execution through automatic, unsanitized import of a tools.py file from the current working directory. Components including call.py (import_tools_from_file()), tool_resolver.py…

  • CVE-2025-59489HigOct 3, 2025
    risk 0.48cvss 7.4epss 0.01

    Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the vulnerable Unity Runtime code, then an…

  • CVE-2025-49124HigJun 16, 2025
    risk 0.48cvss 8.4epss 0.00

    Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0 through 10.1.41, from…

  • CVE-2025-21399HigJan 17, 2025
    risk 0.48cvss 7.4epss 0.01

    Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability

  • CVE-2024-50986HigNov 15, 2024
    risk 0.48cvss 7.3epss 0.01

    An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file.