VYPR

CWE-73

External Control of File Name or Path

BaseDraftLikelihood: High

Description

The product allows user input to control or influence paths or file names that are used in filesystem operations.

Hierarchy (View 1000)

Children

Related attack patterns (CAPEC)

CAPEC-13 · CAPEC-267 · CAPEC-64 · CAPEC-72 · CAPEC-76 · CAPEC-78 · CAPEC-79 · CAPEC-80

CVEs mapped to this weakness (674)

page 4 of 34
  • CVE-2024-5986CriFeb 2, 2026
    risk 0.59cvss 9.1epss 0.01

    A vulnerability in h2oai/h2o-3 version 3.46.0.1 allows remote attackers to write arbitrary data to any file on the server. This is achieved by exploiting the `/3/Parse` endpoint to inject attacker-controlled data as the header of an empty file, which is then exported using the…

  • CVE-2025-65473CriDec 11, 2025
    risk 0.59cvss 9.1epss 0.01

    An arbitrary file rename vulnerability in the /admin/filer.php component of EasyImages 2.0 v2.8.6 and below allows attackers with Administrator privileges to execute arbitrary code via injecting a crafted payload into an uploaded file name.

  • CVE-2025-66257CriNov 26, 2025
    risk 0.59cvss 9.1epss 0.00

    Unauthenticated Arbitrary File Deletion (patch_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform The deletepatch parameter allows unauthenticated…

  • CVE-2025-66254CriNov 26, 2025
    risk 0.59cvss 9.1epss 0.00

    Unauthenticated Arbitrary File Deletion (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform The deleteupgrade parameter allows unauthenticated…

  • CVE-2025-10134CriSep 9, 2025
    risk 0.59cvss 9.1epss 0.01

    The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the alone_import_pack_restore_data() function in all versions up to, and including, 3.2.2. This makes it possible for…

  • CVE-2025-5393CriJul 15, 2025
    risk 0.59cvss 9.1epss 0.01

    The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the alone_import_pack_restore_data() function in all versions up to, and including, 7.8.5. This makes it…

  • CVE-2025-33117CriJun 19, 2025
    risk 0.59cvss 9.1epss 0.01

    IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 could allow a privileged user to modify configuration files that would allow the upload of a malicious autoupdate file to execute arbitrary commands.

  • CVE-2025-2409CriMay 22, 2025
    risk 0.59cvss 9.1epss 0.00

    File corruption vulnerabilities in ASPECT provide attackers access to overwrite sys-tem files if session administrator credentials become compromised This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

  • CVE-2024-6829CriMar 20, 2025
    risk 0.59cvss 9.1epss 0.01

    A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to exploit the `tarfile.extractall()` function to extract the contents of a maliciously crafted tarfile to arbitrary locations on the host server. The attacker can control `repo.path` and `run_hash` to bypass…

  • CVE-2024-10834CriMar 20, 2025
    risk 0.59cvss 9.1epss 0.01

    eosphoros-ai/db-gpt version 0.6.0 contains a vulnerability in the RAG-knowledge endpoint that allows for arbitrary file write. The issue arises from the ability to pass an absolute path to a call to `os.path.join`, enabling an attacker to write files to arbitrary locations on…

  • CVE-2025-0851CriJan 29, 2025
    risk 0.59cvss 9.8epss 0.23

    A path traversal issue in ZipUtils.unzip and TarUtils.untar in Deep Java Library (DJL) on all platforms allows a bad actor to write files to arbitrary locations.

  • CVE-2018-19945CriDec 31, 2020
    risk 0.59cvss 9.1epss 0.01

    A vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6. Caused by improper limitations of a pathname to a restricted directory, this vulnerability allows for renaming arbitrary files on the target system, if exploited. QNAP have already fixed…

  • CVE-2026-67429CriJul 29, 2026
    risk 0.58cvss 10.0epss 0.00

    Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_with_env_config and its FLYTO_SANDBOX_DIR confinement, allowing…

  • CVE-2026-44127HigMay 8, 2026
    risk 0.58cvss —epss 0.16

    SEPPmail Secure Email Gateway before version 15.0.4 contains an unauthenticated path traversal vulnerability in the identifier parameter of /api.app/attachment/preview that allows remote attackers to read arbitrary local files and trigger deletion of files in the targeted…

  • CVE-2026-33309CriMar 24, 2026
    risk 0.58cvss 9.9epss 0.11

    Langflow is a tool for building and deploying AI-powered agents and workflows. Versions 1.2.0 through 1.8.1 have a bypass of the patch for CVE-2025-68478 (External Control of File Name), leading to the root architectural issue within `LocalStorageService` remaining unresolved.…

  • CVE-2011-10030HigAug 20, 2025
    risk 0.58cvss —epss 0.00

    Foxit PDF Reader <  4.3.1.0218 exposes a JavaScript API function, createDataObject(), that allows untrusted PDF content to write arbitrary files anywhere on disk. By embedding a malicious PDF that calls this API, an attacker can drop executables or scripts into privileged…

  • CVE-2026-88899CriSep 10, 2026
    risk 0.57cvss 9.8epss 0.00

    knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to execute file operations outside the project root on the host system.

  • CVE-2026-69355HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

  • CVE-2026-59683CriAug 26, 2026
    risk 0.57cvss 9.8epss 0.01

    The OpenRGB network protocol allows to write attacker controlled strings into arbitrary file system paths (extension of CVE-2026-59682). This allows either a full system compromise from local or remote (if the daemon is running as root) or a full account takeover (if the daemon…

  • CVE-2026-77693HigAug 26, 2026
    risk 0.57cvss 8.7epss 0.00

    The Order Tip for WooCommerce WordPress plugin before 1.6.0 does not check the capability of the user requesting a file deletion, nor does it restrict which path may be deleted, allowing users with the Shop Manager role and above to delete arbitrary files on the server, which…