CWE-73
CVEs classified under CWE-73, newest first.
200 CVEsRSS
CVE-2026-78208High· 7.5exceljs through 4.4.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate file paths
exceljs through 4.4.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate file paths. Attackers can supply arbitrary file paths to read any file accessible to the Node.js process and embed i…
CVE-2026-55477High· 7.23X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation
3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation
GHSA-qp76-pq9f-gr9mHigh· 5.9Duplicate Advisory: Stable FrameNet and NKJP readers parse outside-root XML in 3.9.4
Duplicate Advisory: Stable FrameNet and NKJP readers parse outside-root XML in 3.9.4
CVE-2026-62385Medium· 5.9NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files outside the corpus root by supplying unsafe selectors or poisoned index state
NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files outside the corpus root by supplying unsafe selectors or poisoned index state. Attac…
CVE-2026-63343Critical· 9.9Incus is a system container and virtual machine manager
Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path allows an authenticated Incus user to read or overwrite any file o…
CVE-2026-64679High· 8.1Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks
Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. From 0.19.8 until 0.45.0, Atlantis does not consistently validate user-controlled workspace values supplied through accepted reposi…
CVE-2026-49360HighRecce is a data-validation toolkit for enhanced dbt (data build tool) PR review
Recce is a data-validation toolkit for enhanced dbt (data build tool) PR review. Prior to version 1.50.0, OSS server deployments that expose the server to an untrusted network without authentication are vulnerable to unauthenticated SQL …
CVE-2026-48749Critical· 9.9Incus is a system container and virtual machine manager
Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 fi…
CVE-2026-48750Critical· 9.9Incus is a system container and virtual machine manager
Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the instance. If `e…
CVE-2026-48752Critical· 9.9Incus is a system container and virtual machine manager
Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command executio…
CVE-2026-48753Critical· 9.9Incus is a system container and virtual machine manager
Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary co…
GHSA-ghvf-qf6h-g8x5HighNocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution
NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution
CVE-2026-53451Critical· 9.8Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding
Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated save-waterfall-snapshot Socket.IO command passes attacker-controlled sn…
CVE-2026-49441Critical· 9.1Wazuh is a free and open source platform used for threat prevention, detection, and response
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.3.0 until 4.14.6 and 5.0.0-beta3, the non-merged branch of process_files_from_worker() in framework/wazuh/core/cluster/master.py trusts …
CVE-2026-48162Critical· 9.1Wazuh is a free and open source platform used for threat prevention, detection, and response
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta3, DistributedAPI.send_tmp_file() in framework/wazuh/core/cluster/dapi/dapi.py joins an attacker-controll…
GHSA-w672-239g-c3grHigh· 6.5Duplicate Advisory: GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
Duplicate Advisory: GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
CVE-2026-76222High· 8.2gitpython: GitPython: Arbitrary file creation via path traversal in .gitmodules submodule names (CVE-2026-76222)
A flaw was found in GitPython where it fails to properly validate submodule names within .gitmodules files. A remote attacker could craft a malicious Git repository containing specially formed submodule names with directory traversal seque…
GHSA-cc2g-gq8c-r332High· 7.5grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools
grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools
GHSA-j4r7-8ph4-43g3High· 7.5faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
GHSA-rr55-jp92-8wp2High· 7.5claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
CVE-2026-52875NoneStreambert is a cross-platform Electron Desktop App to stream and download video content
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.6.0, the perform-scheduled-backup IPC handler in src/ipc/storage.js takes settings.path from a renderer-supplied object and uses the res…
CVE-2026-52872High· 8.8Streambert is a cross-platform Electron Desktop App to stream and download video content
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.5.0, the downloadSubtitleFile utility in src/ipc/downloads.js, reached through the run-download IPC channel, accepts a renderer-supplied…
CVE-2026-75830High· 7.1grav-plugin-api (getgrav/grav-plugin-api) versions >= 1.0.0-beta.10 and <= 1.0.14 contain a path traversal vulnerability in the PagesController::batchCopy() method
grav-plugin-api (getgrav/grav-plugin-api) versions >= 1.0.0-beta.10 and <= 1.0.14 contain a path traversal vulnerability in the PagesController::batchCopy() method. An incomplete fix for GHSA-qjq4-jp55-4mx2 left the user-controlled 'suff…
CVE-2026-75913Critical· 9.3CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool
CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter is passed unvalidated into the git show argv without an --end-of-opt…
CVE-2026-48798High· 7.1SSH.NET is a Secure Shell (SSH) library for .NET
SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, DirectoryInfo directoryInfo) trusts file and directory names returned by a remote SCP server and combines them with the r…
CVE-2026-46345High· 8.4compliance-trestle is a tooling platform for managing compliance as code
compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the `-o/--output` argument in `trestle author jinja` allows writing files outside the intended workspace. The application does …
CVE-2026-72842Critical· 9.9luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks
luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit path traversal via `/.%…
CVE-2026-72841Critical· 9.9luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory
luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory. Attackers can upload malicious …
CVE-2026-45725Highcompliance-trestle is a tooling platform for managing compliance as code
compliance-trestle is a tooling platform for managing compliance as code. Prior to versiions 3.12.2 and 4.0.3, the compliance-trestle library's remote fetching cache mechanism (HTTPSFetcher and SFTPFetcher) constructs the local cache fil…
CVE-2026-65941High· 8.8In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.
In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.