VYPR

CWE-73

External Control of File Name or Path

BaseDraftLikelihood: High

Description

The product allows user input to control or influence paths or file names that are used in filesystem operations.

Hierarchy (View 1000)

Children

Related attack patterns (CAPEC)

CAPEC-13 · CAPEC-267 · CAPEC-64 · CAPEC-72 · CAPEC-76 · CAPEC-78 · CAPEC-79 · CAPEC-80

CVEs mapped to this weakness (561)

page 27 of 29
  • CVE-2026-15736HigJul 14, 2026
    risk 0.00cvss 8.3epss 0.00

    Snowflake SQLAlchemy versions prior to 1.11.0 contain several security vulnerabilities, including: Improper handling of user-supplied column identifiers in merge operations could allow SQL injection through attacker-controlled input keys. An attacker may be able to exploit this…

  • CVE-2026-57898CriJul 14, 2026
    risk 0.00cvss 9.0epss 0.00

    In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauthenticated arbitrary file write through the AAS thumbnail API. The AAS thumbnail upload path accepted a client-controlled…

  • CVE-2026-61462HigJul 13, 2026
    risk 0.00cvss 8.6epss 0.00

    mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can supply crafted job_id values like ../../../user to escape the intended path prefix and access…

  • CVE-2026-13014CriJul 13, 2026
    risk 0.00cvss epss 0.00

    A vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated attacker to execute arbitrary code and arbitrarily overwrite writable application files—including Python modules, configuration files, cron inputs, and runtime…

  • CVE-2026-15540MedJul 13, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function of the file /admin/index.php of the component Administrative Interface. Performing a manipulation of the argument page results in improper control of filename…

  • CVE-2026-59793HigJul 10, 2026
    risk 0.00cvss 8.8epss 0.00

    In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration

  • CVE-2026-58192HigJul 8, 2026
    risk 0.00cvss 8.6epss 0.00

    Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 1.1.6, the Appium storage plugin exposes POST /storage/delete, whose handler passes the user-supplied name value directly into path.join(storageRoot, name)…

  • CVE-2026-59807MedJul 8, 2026
    risk 0.00cvss 6.8epss 0.00

    Composio SDK before 0.2.32-beta.283 contains a path validation bypass vulnerability that allows attackers to read and exfiltrate sensitive files by exploiting a missing assertSafeFileUploadPath check in the readFileFromDisk function within tool-file-uploads.ts. Attackers can…

  • CVE-2026-49145HigJul 8, 2026
    risk 0.00cvss 7.5epss 0.00

    App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc. ack searches up the directory hierarchy from the current directory for a project .ackrc and loads its options. The project-source option blocklist in App::Ack::ConfigLoader does…

  • CVE-2026-6101HigJul 7, 2026
    risk 0.00cvss 7.5epss 0.01

    The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Arbitrary File Write in versions up to and including 1.1.12. This is due to unsafe ZIP file extraction in the ampforwp_save_local_font() function combined with inadequate cleanup that fails to…

  • CVE-2026-53648MedJul 7, 2026
    risk 0.00cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.1, downloadable product files are stored using a deterministic filename-derived path. When an administrator uploads a file for a downloadable product, FOSSBilling stores the file as…

  • CVE-2026-59196HigJul 6, 2026
    risk 0.00cvss 7.1epss 0.00

    pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockfile alias could be joined directly under a hoisted node_modules directory. Traversal aliases could escape that directory, while reserved aliases such as .bin or .pnpm could overwrite pnpm-owned layout. This…

  • CVE-2026-58293HigJul 3, 2026
    risk 0.00cvss 8.1epss 0.00

    External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-8921HigJul 3, 2026
    risk 0.00cvss epss 0.00

    External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary code with SYSTEM privileges via a tampered IPC message. Refer to the ' Security Update for ASUS Business Manager ' section on the ASUS Security Advisory for…

  • CVE-2026-5821HigJul 2, 2026
    risk 0.00cvss 8.1epss 0.00

    The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to and including 1.7.4. This is due to insufficient path validation in the Image_Backup::remove() function where backup file paths stored in post meta are used directly in file…

  • CVE-2026-6070CriJul 1, 2026
    risk 0.00cvss 9.1epss 0.00

    The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions up to and including 4.0.1. This is due to insufficient path validation in the remove() method of the JBusinessDirectoryControllerUpload class. The…

  • CVE-2026-3602MedJun 30, 2026
    risk 0.00cvss 4.7epss 0.00

    IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 is vulnerable to SQL injection. A remote attacker could socially engineer a user into accidentally creating files they may not be…

  • CVE-2026-10816HigJun 30, 2026
    risk 0.00cvss 7.5epss 0.00

    Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is enabled

  • CVE-2026-13748MedJun 29, 2026
    risk 0.00cvss 6.3epss 0.00

    Improper restriction of file path resolution in Snowflake CLI versions prior to 3.19 allowed arbitrary local file content to be read and transmitted to Snowflake services. An attacker could exploit this by supplying crafted repository or project content that referenced files…

  • CVE-2026-8095HigJun 28, 2026
    risk 0.00cvss 8.1epss 0.00

    The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. This is due to a case-sensitive bypass of the wpfm_dir_path parameter sanitization in the wpfm_file_meta_update AJAX handler, where…