Threats Tagged 'cwe-73'
View all threats tagged with 'cwe-73'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-73'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-53632: CWE-73: External Control of File Name or Path in vitejs launch-editorCVE-2026-53632 0 launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a UNC path is opened, Windows automatically attempts NTLM authentication to the remote host, causing the user’s NTLMv2 password hash to be leaked to an attacker-controlled SMB server. This can result in credential compromise through offline hash cracking. This vulnerability is fixed in 2.14.1. Join the discussion | CVE Database V5 | 06/22/2026, 15:54:09 UTC Added: 06/22/2026, 17:39:39 UTC |
CVE-2026-49358: CWE-73: External Control of File Name or Path in pontedilana php-weasyprintCVE-2026-49358 0 PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `AbstractGenerator::$temporaryFiles` is a public array, and `removeTemporaryFiles()` — invoked from `__destruct()` and from a registered shutdown function — calls `unlink()` on every entry without verifying that the path is contained within the temporary folder. Any code holding a reference to a generator instance can push an arbitrary path into the array and have it deleted on script shutdown. This mirrors the KnpLabs/snappy issue GHSA-87qc-37cw-84h4. PhpWeasyPrint version 2.6.0 contains a patch for the issue. Join the discussion | CVE Database V5 | 06/19/2026, 14:52:05 UTC Added: 06/19/2026, 15:05:18 UTC |
CVE-2026-53915: CWE-73 in JetBrains GoLandCVE-2026-53915 0 In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration Join the discussion | CVE Database V5 | 06/19/2026, 11:49:40 UTC Added: 06/19/2026, 12:50:12 UTC |
CVE-2026-8118: CWE-73 External Control of File Name or Path in wproyal Royal Addons for Elementor – Addons and Templates Kit for ElementorCVE-2026-8118 0 The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Arbitrary File Read in versions 1.7.1058 through 1.7.1059. This is due to the wpr_get_csv_handle() helper (introduced in version 1.7.1058 as part of the patch for CVE-2026-6229) falling back to is_readable() and fopen($source, 'r') on the attacker-controlled settings.table_upload_csv.url value when it does not parse as an HTTP URL, with no allow-list, traversal block, or extension check. This makes it possible for authenticated attackers, with Contributor-level access and above, to save a crafted wpr-data-table widget through Elementor's save_builder endpoint and have the rendered preview return the line-by-line contents of any file readable by the PHP process, including wp-config.php. Join the discussion | CVE Database V5 | 06/19/2026, 04:31:34 UTC Added: 06/19/2026, 06:20:09 UTC |
CVE-2026-11752: CWE-73 in LY Corporation ArmeriaCVE-2026-11752 0 A vulnerability has been identified in armeria-xds versions 1.38.0 through 1.39.0, where DataSourceStream in the xDS module can resolve control-plane-supplied filenames and environment variables without restriction, allowing a compromised or semi-trusted xDS control plane to read arbitrary local files and environment variables on the xDS client host. Join the discussion | CVE Database V5 | 06/19/2026, 04:29:31 UTC Added: 06/19/2026, 06:20:05 UTC |
CVE-2025-52465: CWE-73: External Control of File Name or Path in geoserver org.geoserver.web:gs-web-appCVE-2025-52465 0 GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.27.3, a vulnerability exists that allows an authenticated administrator with access to GeoServer's security system to pass arbitrary file names to the Master Password Dump web page and create files containing the master password in plaintext. The provided file name must be an absolute path to the target file, the target file can not already exist and all parent directories must already exist. Versions 2.26.4 and 2.27.3 contain a fix. GeoServer installations where the web interface is either disabled or completely removed are not affected since the vulnerability exists in one of the web pages. Join the discussion | CVE Database V5 | 06/18/2026, 14:28:41 UTC Added: 06/18/2026, 15:20:12 UTC |
CVE-2026-10303: CWE-73 External control of file name or path in ServerCo getsslCVE-2026-10303 0 In ServerCo getssl version 2.49 and prior, the ACME challenge token returned to the client was not strictly validated against RFC 8555 before being used in challenge-file handling, allowing a maliciously crafted token to influence local path/filename usage during validation. An attacker who can supply ACME challenge responses to getssl (for example, a malicious or compromised CA endpoint, or an on-path adversary able to tamper with that response path) could exploit this to achieve unauthorized file write/path traversal effects, usually with elevated privileges, ultimately allowing for remote command injection. This issue appears related in spirit to CVE-2023-38198, and is an instance of CWE-73, "External control of file name or path." Other ACME shell script handlers may be affected by similar issues. Join the discussion | CVE Database V5 | 06/16/2026, 18:24:43 UTC Added: 06/16/2026, 19:30:44 UTC |
CVE-2026-34030: CWE-73 External control of file name or path in Wertheim GmbH Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System)CVE-2026-34030 0 The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, does not sufficiently validate the branch code when a new branch is created. The branch code is later used in multiple application functions, including filesystem path generation for uploaded files, profile pictures, and settings. An authenticated attacker with the settings_branches_manage privilege can include path traversal sequences in the branch code and influence the final filesystem location used by affected file operations. This can allow files to be stored in unintended locations, subject to service-account write permissions and branch-code length restrictions. Join the discussion | CVE Database V5 | 06/15/2026, 10:05:36 UTC Added: 06/15/2026, 12:00:24 UTC |
CVE-2026-11527: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in SHLOMIF Config::IniFilesCVE-2026-11527 0 Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandle. Config::IniFiles::_make_filehandle opens a filename argument with Perl's 2-arg open(), so a filename that begins or ends with a pipe ("| cmd", "cmd |") or begins with a redirect ("> path", ">> path") is run as a command or redirect rather than opened as a file. The helper is the open path behind the documented -file argument: new(-file => $thing) reaches it through ReadConfig. An in-memory scalar reference (-file => \$text) does not open a path and is unaffected. Any caller that forwards untrusted input to the -file argument can run an arbitrary command or truncate a file under the process UID. Join the discussion | CVE Database V5 | 06/14/2026, 11:40:45 UTC Added: 06/14/2026, 12:09:27 UTC |
CVE-2026-11526: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in RURBAN GDCVE-2026-11526 0 GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle. GD::Image::_make_filehandle opens a filename argument with Perl's 2-arg open(), so a filename that begins or ends with a pipe ("| cmd", "cmd |") or begins with a redirect ("> path", ">> path") is run as a command or redirect rather than opened as a file. _make_filehandle is the single open path behind every filename-accepting constructor (new, newFromPng, newFromJpeg, and the rest); the in-memory *Data variants do not open a path and are unaffected. Any caller that forwards untrusted input to one of these constructors as a pathname can run an arbitrary command or truncate a file under the process UID. Join the discussion | CVE Database V5 | 06/14/2026, 11:39:21 UTC Added: 06/14/2026, 12:09:27 UTC |
Showing 1 to 10 of 31 results