On this page
CWE-73: External Control of File Name or Path
Weakness Summary
The product allows user input to control or influence paths or file names that are used in filesystem operations.
- Canonical source: MITRE CWE-73 (opens in a new tab)
- Published Atomicorp CVE observations: 39
- Distinct affected products in those observations: 35
- Active Atomicorp rules associated with this weakness: 43
Atomicorp Research Context
Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.
The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.
A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.
Selected Published CVE Observations
| CVE | Vulnerability | Product | Atomicorp finding | Observed rules |
|---|---|---|---|---|
| CVE-2026-58192 | Appium: Unauthenticated arbitrary file/directory deletion in @appium/storage-plugin | appium/storage-plugin | Attack Blocked by Atomicorp | 340007 , 344360 |
| CVE-2018-17246 | Kibana - Local File Inclusion | kibana | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2023-3643 | CAREL Boss Mini <= 1.4.0 - Local File Inclusion | boss-mini | Attack Blocked by Atomicorp | 344360 , 390709 |
| CVE-2023-4634 | Media Library Assistant < 3.09 - Remote Code Execution/Local File Inclusion | media library assistant | Attack Blocked by Atomicorp | 300017 |
| CVE-2025-71334 | Flowise - Path Traversal | flowise | Attack Blocked by Atomicorp | 340007 |
| CVE-2026-86189 | WWBN AVideo Unauthenticated Path Traversal via notify.ffmpeg.json.php | AVideo | Attack Blocked by Atomicorp | 340007 , 344360 , 390709 |
| CVE-2026-48162 | Wazuh: cluster peer can read arbitrary master files and forge offline REST API administrator tokens via DAPI tmp_file pa | wazuh | Attack Blocked by Atomicorp | 340007 , 344360 , 350591 , 390709 |
| CVE-2026-53581 | ntp: write path traversal | core | Attack Blocked by Atomicorp | 340007 , 344360 , 390709 |
| CVE-2026-60009 | theia Arbitrary Code Execution Vulnerability | theia | Attack Blocked by Atomicorp | 351000 |
| CVE-2025-71324 | Flowise - Path Traversal | flowise | Attack Blocked by Atomicorp | 340007 |
| CVE-2026-62865 | TypeBot: Arbitrary server file read via Send Email block attachment path | typebot.io | Attack Blocked by Atomicorp | 340007 , 344360 , 390709 |
| CVE-2022-24900 | Piano LED Visualizer 1.3 - Local File Inclusion | piano led visualizer | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-35032 | Jellyfin: Potential SSRF + Arbitrary file read via LiveTV M3U tuner | jellyfin | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-34522 | SillyTavern: Path traversal in /api/chats/import allows arbitrary file write outside intended chat directory | sillytavern | Attack Blocked by Atomicorp | 340007 , 344360 , 390709 |
| CVE-2026-53580 | Trilium arbitrary file read and denial of service via file:// URLs in the automatic image-download feature | Trilium | Attack Blocked by Atomicorp | 340007 , 347009 |
| CVE-2026-64679 | Atlantis: Path Traversal in Atlantis Workspace Handling Allows Out-of-Bounds Directory Deletion/Creation | atlantis | Attack Blocked by Atomicorp | 340007 , 344360 , 390709 |
| CVE-2024-5334 | Devika - Local File Inclusion | devika | Attack Blocked by Atomicorp | 344360 , 347009 , 390709 |
| CVE-2025-59049 | Mockoon < 9.2.0 - Path Traversal | mockoon | Attack Blocked by Atomicorp | 347009 |
| CVE-2026-19913 | Kaltura HTML5 Video Player, html5lib library Improper Input Validation Vulnerability | Kaltura HTML5 Video Player, html5lib library | Attack Blocked by Atomicorp | 340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008 |
| CVE-2026-29962 | HSC MailInspector - Local File Inclusion | mailinspector | Attack Blocked by Atomicorp | 344360 , 347009 , 390709 |
| CVE-2026-35174 | Chyrp Lite has a Path Traversal to Remote Code Execution | chyrp lite | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-85160 | AVideo through c91b5975d CSRF and Path Traversal via stopLive.php | AVideo | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-45725 | compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal | compliance-trestle | Attack Blocked by Atomicorp | 347009 |
| CVE-2026-75830 | grav-plugin-api before 1.0.15 Path Traversal via batchCopy | grav | Attack Blocked by Atomicorp | 340007 , 344360 |
| CVE-2026-76210 | phpMyFAQ before v4.1.6 Local File Disclosure via PDF Export | phpmyfaq | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-54134 | OctoPrint: File exfiltration possible via query parameters on upload endpoints | OctoPrint | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-35593 | Trilium Notes has Local File Inclusion via upload modified file API endpoint | Trilium | Attack Blocked by Atomicorp | 340007 , 344360 , 390709 |
| CVE-2026-46397 | haxcms-php Local File Inclusion via saveOutline API Location Parameter v2.0 | haxcms-php | Attack Blocked by Atomicorp | 340007 , 344360 , 390709 |
| CVE-2026-75602 | OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool | OpenList | Attack Blocked by Atomicorp | 340007 , 344360 , 390709 |
| CVE-2026-79653 | Eclipse SW360 Path Traversal Vulnerability | Eclipse SW360 | Attack Blocked by Atomicorp | 340007 , 344360 , 390709 |
| CVE-2026-40605 | Tautulli Vulnerable to Authenticated Path Traversal in Cache Deletion API | Tautulli | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-10694 | SourceCodester Online Food Ordering System index.php include file inclusion | Online Food Ordering System | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2023-30943 | Moodle - Cross-Site Scripting/Remote Code Execution | moodle | Attack Blocked by Atomicorp | 333141 , 340007 , 340099 , 340147 , 340148 , 340149 , 341099 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148 |
| CVE-2026-34967 | Adminer sql-log Plugin 5.3.0 through 5.4.2 Arbitrary File Write | adminer | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2021-24966 | WordPress Plugin Error Log Viewer 1.1.1 - Arbitrary File Clearing (Authenticated) | error log viewer | Attack Blocked by Atomicorp | 336461 , 344360 , 381206 |
| CVE-2026-41412 | alf.io vulnerable to Arbitrary File Read and Exfil via simpleHttpClient Extension Script | alf.io | Attack Blocked by Atomicorp | 344360 |
| CVE-2026-10558 | SourceCodester Pizzafy Ecommerce System index.php file inclusion | Pizzafy Ecommerce System | Attack Blocked by Atomicorp | 344360 , 347009 |
| CVE-2026-10559 | SourceCodester Pizzafy Ecommerce System index.php file inclusion | Pizzafy Ecommerce System | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-19353 | DedeCMS Installation Wizard index.php _4_Setup file inclusion | DedeCMS | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 |
Associated Atomicorp WAF Rules
| Rule | Status | Behavior |
|---|---|---|
| 300017 | Active | disruptive (deny) |
| 333141 | Active | disruptive (deny) |
| 336461 | Active | disruptive (deny) |
| 337109 | Active | disruptive (deny) |
| 337110 | Active | disruptive (deny) |
| 340007 | Active | disruptive (deny) |
| 340014 | Active | disruptive (deny) |
| 340023 | Active | disruptive (deny) |
| 340029 | Active | disruptive (deny) |
| 340099 | Active | disruptive (deny) |
| 340147 | Active | disruptive (deny) |
| 340148 | Active | disruptive (deny) |
| 340149 | Active | disruptive (deny) |
| 340193 | Active | disruptive (deny) |
| 341099 | Active | disruptive (deny) |
| 341256 | Active | disruptive (deny) |
| 342259 | Active | disruptive (deny) |
| 344360 | Active | disruptive (deny) |
| 344361 | Active | disruptive (deny) |
| 344362 | Active | disruptive (deny) |
| 344363 | Active | disruptive (deny) |
| 344364 | Active | disruptive (deny) |
| 344365 | Active | disruptive (deny) |
| 344366 | Active | disruptive (deny) |
| 344370 | Active | disruptive (deny) |
| 344380 | Active | disruptive (deny) |
| 344382 | Active | disruptive (deny) |
| 344385 | Active | disruptive (deny) |
| 346755 | Active | disruptive (deny) |
| 347009 | Active | disruptive (deny) |
| 347198 | Active | disruptive (deny) |
| 350147 | Active | disruptive (deny) |
| 350148 | Active | disruptive (deny) |
| 350591 | Active | disruptive (deny) |
| 351000 | Active | disruptive (deny) |
| 381206 | Active | disruptive (deny) |
| 390613 | Active | disruptive (deny) |
| 390614 | Active | disruptive (deny) |
| 390709 | Active | disruptive (deny) |
| 390722 | Active | disruptive (deny) |
| 398008 | Active | non-disruptive (pass) |
| 398021 | Active | disruptive (deny) |
| 398022 | Active | disruptive (deny) |
Related MITRE CAPEC Context
MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims:
CAPEC-13 (opens in a new tab) , CAPEC-267 (opens in a new tab) , CAPEC-64 (opens in a new tab) , CAPEC-72 (opens in a new tab) , CAPEC-76 (opens in a new tab) , CAPEC-78 (opens in a new tab) , CAPEC-79 (opens in a new tab) , CAPEC-80 (opens in a new tab)