On this page

CWE-73: External Control of File Name or Path

Weakness Summary

The product allows user input to control or influence paths or file names that are used in filesystem operations.

  • Canonical source: MITRE CWE-73 (opens in a new tab)
  • Published Atomicorp CVE observations: 39
  • Distinct affected products in those observations: 35
  • Active Atomicorp rules associated with this weakness: 43

Atomicorp Research Context

Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.

The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.

A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.

Selected Published CVE Observations

CVEVulnerabilityProductAtomicorp findingObserved rules
CVE-2026-58192Appium: Unauthenticated arbitrary file/directory deletion in @appium/storage-pluginappium/storage-pluginAttack Blocked by Atomicorp340007 , 344360
CVE-2018-17246Kibana - Local File InclusionkibanaAttack Blocked by Atomicorp340007 , 344360 , 347009 , 390709
CVE-2023-3643CAREL Boss Mini <= 1.4.0 - Local File Inclusionboss-miniAttack Blocked by Atomicorp344360 , 390709
CVE-2023-4634Media Library Assistant < 3.09 - Remote Code Execution/Local File Inclusionmedia library assistantAttack Blocked by Atomicorp300017
CVE-2025-71334Flowise - Path TraversalflowiseAttack Blocked by Atomicorp340007
CVE-2026-86189WWBN AVideo Unauthenticated Path Traversal via notify.ffmpeg.json.phpAVideoAttack Blocked by Atomicorp340007 , 344360 , 390709
CVE-2026-48162Wazuh: cluster peer can read arbitrary master files and forge offline REST API administrator tokens via DAPI tmp_file pawazuhAttack Blocked by Atomicorp340007 , 344360 , 350591 , 390709
CVE-2026-53581ntp: write path traversalcoreAttack Blocked by Atomicorp340007 , 344360 , 390709
CVE-2026-60009theia Arbitrary Code Execution VulnerabilitytheiaAttack Blocked by Atomicorp351000
CVE-2025-71324Flowise - Path TraversalflowiseAttack Blocked by Atomicorp340007
CVE-2026-62865TypeBot: Arbitrary server file read via Send Email block attachment pathtypebot.ioAttack Blocked by Atomicorp340007 , 344360 , 390709
CVE-2022-24900Piano LED Visualizer 1.3 - Local File Inclusionpiano led visualizerAttack Blocked by Atomicorp340007 , 344360 , 347009 , 390709
CVE-2026-35032Jellyfin: Potential SSRF + Arbitrary file read via LiveTV M3U tunerjellyfinAttack Blocked by Atomicorp337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-34522SillyTavern: Path traversal in /api/chats/import allows arbitrary file write outside intended chat directorysillytavernAttack Blocked by Atomicorp340007 , 344360 , 390709
CVE-2026-53580Trilium arbitrary file read and denial of service via file:// URLs in the automatic image-download featureTriliumAttack Blocked by Atomicorp340007 , 347009
CVE-2026-64679Atlantis: Path Traversal in Atlantis Workspace Handling Allows Out-of-Bounds Directory Deletion/CreationatlantisAttack Blocked by Atomicorp340007 , 344360 , 390709
CVE-2024-5334Devika - Local File InclusiondevikaAttack Blocked by Atomicorp344360 , 347009 , 390709
CVE-2025-59049Mockoon < 9.2.0 - Path TraversalmockoonAttack Blocked by Atomicorp347009
CVE-2026-19913Kaltura HTML5 Video Player, html5lib library Improper Input Validation VulnerabilityKaltura HTML5 Video Player, html5lib libraryAttack Blocked by Atomicorp340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008
CVE-2026-29962HSC MailInspector - Local File InclusionmailinspectorAttack Blocked by Atomicorp344360 , 347009 , 390709
CVE-2026-35174Chyrp Lite has a Path Traversal to Remote Code Executionchyrp liteAttack Blocked by Atomicorp340007 , 344360 , 347009 , 390709
CVE-2026-85160AVideo through c91b5975d CSRF and Path Traversal via stopLive.phpAVideoAttack Blocked by Atomicorp340007 , 344360 , 347009 , 390709
CVE-2026-45725compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversalcompliance-trestleAttack Blocked by Atomicorp347009
CVE-2026-75830grav-plugin-api before 1.0.15 Path Traversal via batchCopygravAttack Blocked by Atomicorp340007 , 344360
CVE-2026-76210phpMyFAQ before v4.1.6 Local File Disclosure via PDF ExportphpmyfaqAttack Blocked by Atomicorp340007 , 344360 , 347009 , 390709
CVE-2026-54134OctoPrint: File exfiltration possible via query parameters on upload endpointsOctoPrintAttack Blocked by Atomicorp340007 , 344360 , 347009 , 390709
CVE-2026-35593Trilium Notes has Local File Inclusion via upload modified file API endpointTriliumAttack Blocked by Atomicorp340007 , 344360 , 390709
CVE-2026-46397haxcms-php Local File Inclusion via saveOutline API Location Parameter v2.0haxcms-phpAttack Blocked by Atomicorp340007 , 344360 , 390709
CVE-2026-75602OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download toolOpenListAttack Blocked by Atomicorp340007 , 344360 , 390709
CVE-2026-79653Eclipse SW360 Path Traversal VulnerabilityEclipse SW360Attack Blocked by Atomicorp340007 , 344360 , 390709
CVE-2026-40605Tautulli Vulnerable to Authenticated Path Traversal in Cache Deletion APITautulliAttack Blocked by Atomicorp340007 , 344360 , 347009 , 390709
CVE-2026-10694SourceCodester Online Food Ordering System index.php include file inclusionOnline Food Ordering SystemAttack Blocked by Atomicorp340007 , 344360 , 347009 , 390709
CVE-2023-30943Moodle - Cross-Site Scripting/Remote Code ExecutionmoodleAttack Blocked by Atomicorp333141 , 340007 , 340099 , 340147 , 340148 , 340149 , 341099 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2026-34967Adminer sql-log Plugin 5.3.0 through 5.4.2 Arbitrary File WriteadminerAttack Blocked by Atomicorp340007 , 344360 , 347009 , 390709
CVE-2021-24966WordPress Plugin Error Log Viewer 1.1.1 - Arbitrary File Clearing (Authenticated)error log viewerAttack Blocked by Atomicorp336461 , 344360 , 381206
CVE-2026-41412alf.io vulnerable to Arbitrary File Read and Exfil via simpleHttpClient Extension Scriptalf.ioAttack Blocked by Atomicorp344360
CVE-2026-10558SourceCodester Pizzafy Ecommerce System index.php file inclusionPizzafy Ecommerce SystemAttack Blocked by Atomicorp344360 , 347009
CVE-2026-10559SourceCodester Pizzafy Ecommerce System index.php file inclusionPizzafy Ecommerce SystemAttack Blocked by Atomicorp340007 , 344360 , 347009 , 390709
CVE-2026-19353DedeCMS Installation Wizard index.php _4_Setup file inclusionDedeCMSAttack Blocked by Atomicorp340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370

Associated Atomicorp WAF Rules

RuleStatusBehavior
300017Activedisruptive (deny)
333141Activedisruptive (deny)
336461Activedisruptive (deny)
337109Activedisruptive (deny)
337110Activedisruptive (deny)
340007Activedisruptive (deny)
340014Activedisruptive (deny)
340023Activedisruptive (deny)
340029Activedisruptive (deny)
340099Activedisruptive (deny)
340147Activedisruptive (deny)
340148Activedisruptive (deny)
340149Activedisruptive (deny)
340193Activedisruptive (deny)
341099Activedisruptive (deny)
341256Activedisruptive (deny)
342259Activedisruptive (deny)
344360Activedisruptive (deny)
344361Activedisruptive (deny)
344362Activedisruptive (deny)
344363Activedisruptive (deny)
344364Activedisruptive (deny)
344365Activedisruptive (deny)
344366Activedisruptive (deny)
344370Activedisruptive (deny)
344380Activedisruptive (deny)
344382Activedisruptive (deny)
344385Activedisruptive (deny)
346755Activedisruptive (deny)
347009Activedisruptive (deny)
347198Activedisruptive (deny)
350147Activedisruptive (deny)
350148Activedisruptive (deny)
350591Activedisruptive (deny)
351000Activedisruptive (deny)
381206Activedisruptive (deny)
390613Activedisruptive (deny)
390614Activedisruptive (deny)
390709Activedisruptive (deny)
390722Activedisruptive (deny)
398008Activenon-disruptive (pass)
398021Activedisruptive (deny)
398022Activedisruptive (deny)

MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims:

CAPEC-13 (opens in a new tab) , CAPEC-267 (opens in a new tab) , CAPEC-64 (opens in a new tab) , CAPEC-72 (opens in a new tab) , CAPEC-76 (opens in a new tab) , CAPEC-78 (opens in a new tab) , CAPEC-79 (opens in a new tab) , CAPEC-80 (opens in a new tab)