CWE-73
CVEs classified under CWE-73, newest first.
200 CVEsRSS
CVE-2026-59819Medium· 4.9LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.10-stable, LiteLLM's /health/test_connection endpoint resolved request-supplied environment and OIDC file references in litellm_params, a…
CVE-2026-45016Medium· 6.5EGroupware Vulnerable to Local File Inclusion via file:// URI in Mail Compose
EGroupware Vulnerable to Local File Inclusion via file:// URI in Mail Compose
CVE-2026-8921High· 8.5External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary code with SYSTEM privileges via a tampered IPC message. Refer to the ' Security Update for ASUS Business Manager ' sect…
External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary code with SYSTEM privileges via a tampered IPC message. Refer to the ' Security Update for ASUS Business Manager ' sect…
CVE-2026-58293High· 8.1Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-9559Critical· 9.9Mautic vulnerable to Path Traversal via Campaign Import
Mautic vulnerable to Path Traversal via Campaign Import
CVE-2026-50162Medium· 5.3oras-go: oras-go: File store write outside working directory via symlink traversal (CVE-2026-50162)
A flaw was found in oras-go. The file content store, intended to confine writes to a specified working directory, does not properly account for symbolic link (symlink) traversal. A remote attacker, by providing a specially crafted blob tit…
GHSA-2wwr-9x6f-88gpMedium· 5.3EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
GHSA-fr4h-3cph-29xvHigh· 7.1pnpm: Hoisted install imports lockfile alias outside node_modules
pnpm: Hoisted install imports lockfile alias outside node_modules
GHSA-72r4-9c5j-mj57High· 7.1pnpm: `patch-remove` could delete project-selected files outside the patches directory
pnpm: `patch-remove` could delete project-selected files outside the patches directory
CVE-2026-47214High· 7.1Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.94.0, the HTML backend has unsafe URI and path handling. This vulnerability is fixed in 2.94.0.
CVE-2026-49358Low· 3.0PhpWeasyPrint vulnerable to arbitrary file deletion at shutdown via public $temporaryFiles
PhpWeasyPrint vulnerable to arbitrary file deletion at shutdown via public $temporaryFiles
CVE-2026-55699Medium· 6.5pnpm: Reserved bin name deletes PNPM_HOME during global remove
pnpm: Reserved bin name deletes PNPM_HOME during global remove
CVE-2026-55700High· 7.1pnpm: `stage download` writes outside its destination directory via manifest name/version traversal
pnpm: `stage download` writes outside its destination directory via manifest name/version traversal
CVE-2025-71338Critical· 10.0PoCFlowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write files outside the storage directory
Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write files outside the storage directory. Attackers can use parent-directory sequences to escape the stor…
CVE-2026-54134HighOctoPrint has possible file exfiltration via query parameters on upload endpoints
OctoPrint has possible file exfiltration via query parameters on upload endpoints
GHSA-2h46-9x5w-4wf7MediumEntire CLI: Path traversal in checkpoint session metadata allows arbitrary file write during resume/rewind
Entire CLI: Path traversal in checkpoint session metadata allows arbitrary file write during resume/rewind
GHSA-2fmp-9rvw-hc96High· 7.1Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning
Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning
GHSA-f44v-7qgw-9gh9High· 8.1PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion
PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion
GHSA-p6gq-j5cr-w38fHigh· 7.1Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message
Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message
CVE-2026-12568Medium· 6.5BBOT: Arbitrary File Write in postman_download Module
BBOT: Arbitrary File Write in postman_download Module
CVE-2026-11752MediumArmeria: External Control of File Name or Path in xDS SDS DataSource
Armeria: External Control of File Name or Path in xDS SDS DataSource
CVE-2026-2604Medium· 5.6PoCA flaw was found in evolution-data-server
A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored…
CVE-2026-48520Medium· 6.1Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read
Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read
CVE-2026-53632Mediumlaunch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
CVE-2025-52465High· 7.2GeoServer has an arbitrary file write vulnerability in its Master Password Dump Page
GeoServer has an arbitrary file write vulnerability in its Master Password Dump Page
CVE-2026-47643Critical· 9.8Azure Stack Edge Remote Code Execution Vulnerability
External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network.
CVE-2026-35080High· 8.1The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
CVE-2026-35079High· 8.1The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
CVE-2026-35078High· 8.1The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
CVE-2026-35077High· 8.1The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.