VYPR

CWE-426

Untrusted Search Path

BaseStableLikelihood: High

Description

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-38

CVEs mapped to this weakness (672)

page 33 of 34
  • CVE-2026-48391HigJul 28, 2026
    risk 0.00cvss 8.2epss 0.00

    Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user…

  • CVE-2026-48287HigJul 14, 2026
    risk 0.00cvss 7.4epss 0.00

    CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in…

  • CVE-2026-48275HigJul 14, 2026
    risk 0.00cvss 8.6epss 0.00

    Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

  • CVE-2026-48346HigJul 14, 2026
    risk 0.00cvss 7.9epss 0.00

    Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

  • CVE-2026-57097MedJul 14, 2026
    risk 0.00cvss 6.4epss 0.00

    Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.

  • CVE-2026-15515HigJul 13, 2026
    risk 0.00cvss 7.0epss 0.00

    A security vulnerability has been detected in Tencent PC Manager 18.1.30242.301. This issue affects some unknown processing in the library qmudisk64.sys of the component QMUDisk Driver. The manipulation leads to uncontrolled search path. The attack must be carried out locally.…

  • CVE-2026-49145HigJul 8, 2026
    risk 0.00cvss 7.5epss 0.00

    App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc. ack searches up the directory hierarchy from the current directory for a project .ackrc and loads its options. The project-source option blocklist in App::Ack::ConfigLoader does…

  • CVE-2026-6901HigJul 6, 2026
    risk 0.00cvss 7.7epss 0.00

    Untrusted Search Path vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before R 4.4-01P5.

  • CVE-2026-57919HigJun 29, 2026
    risk 0.00cvss 7.8epss 0.00

    PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DACL that grants GENERIC_READ and GENERIC_WRITE permissions to all authenticated users. A low-privileged local attacker can connect to this pipe and send crafted…

  • CVE-2026-46710HigJun 26, 2026
    risk 0.00cvss 7.8epss 0.00

    Notepad++ is a free and open-source source code editor. From 8.9.4 until 8.9.6, Notepad++ contains a local privilege escalation vulnerability in the installer. During installation, the installer invokes powershell.exe without using an absolute path after setting the working…

  • CVE-2026-29089HigMar 6, 2026
    risk 0.00cvss 8.8epss 0.00

    TimescaleDB is a time-series database for high-performance real-time analytics packaged as a Postgres extension. From version 2.23.0 to 2.25.1, PostgreSQL uses the search_path setting to locate unqualified database objects (tables, functions, operators). If the search_path…

  • CVE-2026-23512HigJan 14, 2026
    risk 0.00cvss 8.6epss 0.00

    SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, there is a Untrusted Search Path vulnerability when Advanced Options setting is trigger. The application executes notepad.exe without specifying an absolute path when using the Advanced Options setting. On…

  • CVE-2023-41105HigAug 23, 2023
    risk 0.00cvss 7.5epss 0.02

    An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed to os.path.normpath(), the path will be truncated unexpectedly at the first '\0' byte. There are plausible cases in which an application would have rejected a filename for security…

  • CVE-2023-23618HigFeb 14, 2023
    risk 0.00cvss 8.6epss 0.00

    Git for Windows is the Windows port of the revision control system Git. Prior to Git for Windows version 2.39.2, when `gitk` is run on Windows, it potentially runs executables from the current directory inadvertently, which can be exploited with some social engineering to trick…

  • CVE-2022-4883HigFeb 7, 2023
    risk 0.00cvss 8.8epss 0.01

    A flaw was found in libXpm. When processing files with .Z or .gz extensions, the library calls external programs to compress and uncompress files, relying on the PATH environment variable to find these programs, which could allow a malicious user to execute other programs by…

  • CVE-2022-39245HigSep 26, 2022
    risk 0.00cvss 8.4epss 0.00

    Mist is the command-line interface for the makedeb Package Repository. Prior to version 0.9.5, a user-provided `sudo` binary via the `PATH` variable can allow a local user to run arbitrary commands on the user's system with root permissions. Versions 0.9.5 and later contain a…

  • CVE-2021-37617HigAug 18, 2021
    risk 0.00cvss 7.3epss 0.00

    The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. The Nextcloud Desktop Client invokes its uninstaller script when being installed to make sure there are no remnants of previous installations. In versions 3.0.3 through 3.2.4, the…

  • CVE-2020-15801CriJul 17, 2020
    risk 0.00cvss 9.8epss 0.03

    In Python 3.8.4, sys.path restrictions specified in a python38._pth file are ignored, allowing code to be loaded from arbitrary locations. The ._pth file (e.g., the python._pth file) is not affected.

  • CVE-2020-11081MedJul 10, 2020
    risk 0.00cvss 5.3epss 0.01

    osquery before version 4.4.0 enables a privilege escalation vulnerability. If a Window system is configured with a PATH that contains a user-writable directory then a local user may write a zlib1.dll DLL, which osquery will attempt to load. Since osquery runs with elevated…

  • CVE-2018-19486CriNov 23, 2018
    risk 0.00cvss 9.8epss 0.04

    Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain cases involving the run_command() API and run-command.c, because there was a dangerous change from execvp to execv during 2017.