VYPR

CWE-73

External Control of File Name or Path

BaseDraftLikelihood: High

Description

The product allows user input to control or influence paths or file names that are used in filesystem operations.

Hierarchy (View 1000)

Children

Related attack patterns (CAPEC)

CAPEC-13 · CAPEC-267 · CAPEC-64 · CAPEC-72 · CAPEC-76 · CAPEC-78 · CAPEC-79 · CAPEC-80

CVEs mapped to this weakness (561)

page 28 of 29
  • CVE-2025-71338CriJun 25, 2026
    risk 0.00cvss 10.0epss 0.01

    Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauthenticated attackers to write arbitrary files to the filesystem. Attackers can exploit unsanitized fileName parameters with ../ sequences to overwrite critical…

  • CVE-2025-71333CriJun 25, 2026
    risk 0.00cvss 9.8epss 0.01

    Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit path traversal in the chatId and chatflowId parameters to upload malicious files to arbitrary…

  • CVE-2026-55477HigJun 25, 2026
    risk 0.00cvss 7.2epss 0.00

    3X-UI is a web control panel for managing Xray-core servers. Prior to 3.3.1, an authenticated administrator can abuse the database import functionality to achieve arbitrary file write on the host by modifying Xray configuration values stored in the database. This can be…

  • CVE-2026-27211CriFeb 21, 2026
    risk 0.00cvss 10.0epss 0.01

    Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. Versions 34.0 through 50.0 arevulnerable to arbitrary host file exfiltration (constrained by process privileges) when using virtio-block devices backed by raw images. A malicious guest can overwrite its disk…

  • CVE-2026-27115HigFeb 20, 2026
    risk 0.00cvss 7.1epss 0.00

    ADB Explorer is a fluent UI for ADB on Windows. Versions 0.9.26020 and below have an unvalidated command-line argument that allows any user to trigger recursive deletion of arbitrary directories on the Windows filesystem. ADB Explorer accepts an optional path argument to set a…

  • CVE-2026-26975HigFeb 20, 2026
    risk 0.00cvss 8.8epss 0.01

    Music Assistant is an open-source media library manager that integrates streaming services with connected speakers. Versions 2.6.3 and below allow unauthenticated network-adjacent attackers to execute arbitrary code on affected installations. The music/playlists/update API…

  • CVE-2026-26202HigFeb 19, 2026
    risk 0.00cvss 7.5epss 0.00

    Penpot is an open-source design tool for design and code collaboration. Prior to version 2.13.2, an authenticated user can read arbitrary files from the server by supplying a local file path (e.g. `/etc/passwd`) as a font data chunk in the `create-font-variant` RPC endpoint,…

  • CVE-2026-25964MedFeb 13, 2026
    risk 0.00cvss 4.9epss 0.00

    Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.5.1, a Path Traversal vulnerability in the RecipeImport workflow of Tandoor Recipes allows authenticated users with import permissions to read arbitrary files on the…

  • CVE-2026-25636HigFeb 6, 2026
    risk 0.00cvss 8.2epss 0.00

    calibre is an e-book manager. In 9.1.0 and earlier, a path traversal vulnerability in Calibre's EPUB conversion allows a malicious EPUB file to corrupt arbitrary existing files writable by the Calibre process. During conversion, Calibre resolves CipherReference URI from…

  • CVE-2026-22783CriJan 12, 2026
    risk 0.00cvss 9.6epss 0.00

    Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior to 2.4.24, the DFIR-IRIS datastore file management system has a vulnerability where mass assignment of the file_local_name field combined with path trust in…

  • CVE-2025-66449HigDec 16, 2025
    risk 0.00cvss 8.8epss 0.01

    ConvertXis a self-hosted online file converter. In versions prior to 0.16.0, the endpoint `/upload` allows an authenticated user to write arbitrary files on the system, overwriting binaries and allowing code execution. The upload function takes `file.name` directly from user…

  • CVE-2025-30201HigNov 21, 2025
    risk 0.00cvss 7.7epss 0.01

    Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.13.0, a vulnerability in Wazuh Agent allows authenticated attackers to force NTLM authentication through malicious UNC paths in various agent configuration settings,…

  • CVE-2025-58762CriSep 9, 2025
    risk 0.00cvss 9.1epss 0.01

    Tautulli is a Python based monitoring and tracking tool for Plex Media Server. In Tautulli v2.15.3 and earlier, an attacker with administrative access can use the `pms_image_proxy` endpoint to write arbitrary python scripts into the application filesystem. This leads to remote…

  • CVE-2024-5823CriOct 29, 2024
    risk 0.00cvss 9.1epss 0.01

    A file overwrite vulnerability exists in gaizhenbiao/chuanhuchatgpt versions <= 20240410. This vulnerability allows an attacker to gain unauthorized access to overwrite critical configuration files within the system. Exploiting this vulnerability can lead to unauthorized changes…

  • CVE-2024-6714HigJul 23, 2024
    risk 0.00cvss 8.8epss 0.00

    An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate their privilege.

  • CVE-2024-5334HigJun 27, 2024
    risk 0.00cvss 7.5epss 0.02

    A local file read vulnerability exists in the stitionai/devika repository, affecting the latest version. The vulnerability is due to improper handling of the 'snapshot_path' parameter in the '/api/get-browser-snapshot' endpoint. An attacker can exploit this vulnerability by…

  • CVE-2023-1105HigMar 1, 2023
    risk 0.00cvss 8.1epss 0.01

    External Control of File Name or Path in GitHub repository flatpressblog/flatpress prior to 1.3.

  • CVE-2021-3845HigJan 4, 2022
    risk 0.00cvss 7.5epss 0.01

    ws-scrcpy is vulnerable to External Control of File Name or Path

  • CVE-2021-3626HigOct 1, 2021
    risk 0.00cvss 8.8epss 0.00

    The Windows version of Multipass before 1.7.0 allowed any local process to connect to the localhost TCP control socket to perform mounts from the operating system to a guest, allowing for privilege escalation.

  • CVE-2020-15264HigOct 20, 2020
    risk 0.00cvss 8.0epss 0.02

    The Boxstarter installer before version 2.13.0 configures C:\ProgramData\Boxstarter to be in the system-wide PATH environment variable. However, this directory is writable by normal, unprivileged users. To exploit the vulnerability, place a DLL in this directory that a…