By weakness (CWE)

CWE-73: related vulnerabilities

CVEs classified under CWE-73. Understanding the weakness class helps prioritize systemic fixes over one-off patches.

43 published vulnerabilities

  • CVE-2026-48720HIGH 8.8

    Warp, an AI-assisted terminal and development environment, contains a critical file-handling vulnerability that allows attackers to write arbitrary files to a user's system by embedding specially crafted terminal escape sequences in command output. When a user runs a command that contains a malicious OSC 1337 File payload, Warp will silently decode and save the payload as a local file without prompting the user for confirmation. This affects versions from March 2025 through early May 2026, and has been patched in version 0.2026.05.06.15.42.stable_01.

  • CVE-2026-59793HIGH 8.8

    JetBrains TeamCity versions prior to 2026.1.2 contain a flaw in their Perforce version control system integration that allows authenticated users to access files they should not have permission to read. An attacker with valid TeamCity credentials can exploit this to retrieve sensitive files from the server, potentially including configuration data, source code, or other protected assets. This is a post-authentication vulnerability—the attacker must already have a TeamCity account, but the impact is substantial once inside.

  • CVE-2026-11527HIGH 8.6

    Config::IniFiles is a Perl library that reads configuration files in INI format. Versions before 3.001000 contain a critical flaw in how they open configuration files: they use Perl's two-argument open() function, which interprets special characters in filenames as shell commands or file redirections. If an attacker can control the filename passed to the library (via the -file argument), they can execute arbitrary OS commands or overwrite files on the system. The vulnerability affects any application using Config::IniFiles that processes untrusted configuration file paths.

  • CVE-2026-58192HIGH 8.6

    Appium, a popular cross-platform automation framework used for testing mobile and web applications, contains a critical path traversal vulnerability in its storage plugin. An unauthenticated attacker can send specially crafted requests to bypass the storage directory boundary using directory traversal sequences (../) and delete arbitrary files or directories on the affected system. The vulnerability exists in versions prior to 1.1.6 and has been patched in the latest release.

  • CVE-2026-35076HIGH 8.1

    A vulnerability in MBS Solutions gateway and protocol-conversion products allows authenticated users to delete files from the affected system without proper authorization. The flaw exists in the 'bac-scanresult' method, which fails to validate user-supplied input adequately. An attacker who has legitimate credentials can exploit this to remove critical files, potentially disrupting system operations or causing data loss.

  • CVE-2026-35077HIGH 8.1

    A vulnerability in MBS Solutions gateway products allows authenticated users to delete files they shouldn't have access to. An attacker with valid user credentials can exploit the ugw-delete-file method to remove arbitrary files from affected systems by bypassing input validation controls. This is especially concerning in industrial automation environments where these gateways often handle critical protocol conversions and data flows.

  • CVE-2026-35078HIGH 8.1

    A vulnerability in MBS Solutions gateway products allows authenticated users to delete files from affected systems without proper authorization. An attacker with valid user credentials can exploit the ugw-logstop method to remove arbitrary files, potentially disrupting system operations or destroying evidence. This is classified as a high-severity flaw because it requires only standard user access and can cause significant damage to system integrity and availability.

  • CVE-2026-35079HIGH 8.1

    CVE-2026-35079 is a file deletion vulnerability in MBS Solutions' Universal Gateway firmware and related gateway products. An attacker who already has valid user credentials can exploit the ugw-restore method to delete arbitrary files on the device. Because the vulnerability requires existing user access, the risk depends heavily on your organization's internal security posture and whether these devices are exposed to untrusted users.

  • CVE-2026-35080HIGH 8.1

    A flaw in MBS Solutions gateway firmware allows authenticated users to delete files they shouldn't have access to. An attacker with valid login credentials can exploit the ugw-restoreinfo method to remove arbitrary files from affected devices, potentially disrupting operations or destroying critical system data. The vulnerability requires existing user privileges but poses a serious risk to the integrity and availability of gateway-based infrastructure.

  • CVE-2026-46402HIGH 8.1

    Microsoft UFO, an open-source framework for intelligent automation, contains a path traversal vulnerability in version 3.0.1-4-ge2626659. An authenticated user can manipulate task names to write log files and directories outside the intended logs directory, potentially overwriting critical files or gaining unauthorized file system access on the affected system.

  • CVE-2026-5821HIGH 8.1

    The Image Optimizer plugin for WordPress contains a critical flaw that lets authenticated authors delete any file on the web server, not just their backup images. The vulnerability stems from the plugin storing file paths in a database field that users can edit directly, then using those paths without any safety checks when deleting attachments. An author-level user could inject a path to any system file they want removed, and the plugin will dutifully delete it when they remove an image. This affects all versions up to and including 1.7.4.

  • CVE-2026-58293HIGH 8.1

    Microsoft Edge (Chromium-based) contains a vulnerability that allows an attacker to manipulate how files are named or accessed on your system, potentially leading to code execution without requiring the user to do anything special. The vulnerability is network-reachable and carries high severity due to its potential for complete system compromise.

  • CVE-2026-8095HIGH 8.1

    A WordPress plugin called Frontend File Manager contains a security flaw that allows logged-in users with basic subscriber accounts to delete critical files from a website's server. The vulnerability exists because the plugin fails to properly validate file paths when processing deletion requests, enabling attackers to specify any file on the system for removal—including the configuration file that stores database credentials. This could allow a low-privileged attacker to completely disable or take over a website. The flaw affects all versions up to 23.6.

  • CVE-2025-71324HIGH 7.5

    Flowise, an open-source platform for building conversational AI applications, contains a flaw that allows unauthenticated attackers to read files from the server hosting it. The vulnerability exists in file-download endpoints that accept a chatId parameter without properly validating or restricting where files can be retrieved from. An attacker can manipulate this parameter to escape the intended storage directory and access sensitive files elsewhere on the system—most critically, the application's SQLite database, which contains user credentials, conversation histories, and other sensitive data. No user interaction or authentication is required to exploit this.

  • CVE-2026-10816HIGH 7.5

    NetScaler ADC and NetScaler Gateway appliances with management interfaces exposed to the network are vulnerable to unauthenticated attackers reading arbitrary files from the system. An attacker with network access to the management IP address (NSIP, Cluster Management IP, or SNIP configured for management) can exploit a path traversal or similar flaw to extract sensitive files without providing credentials. This is a significant confidentiality risk because management interfaces typically house configuration data, certificates, and other sensitive information.

  • CVE-2026-49145HIGH 7.5

    App::Ack, a popular code-search tool for Perl developers, has a vulnerability in how it handles configuration files. When developers clone or use a project containing a malicious .ackrc configuration file, the tool can be tricked into reading and processing arbitrary files on the system—even those outside the project directory. This happens because the security blocklist that prevents dangerous options in project-level configs is incomplete. An attacker who commits a crafted .ackrc to a repository can exploit this to extract sensitive file contents when other developers run ack.

  • CVE-2026-6101HIGH 7.5

    The AMP for WP plugin, a WordPress extension used to optimize mobile page performance, contains a flaw in how it handles file uploads. When the plugin processes compressed ZIP files containing fonts, it doesn't properly clean up temporary files and directories after extraction. An authenticated WordPress user with Author-level permissions or higher can exploit this to upload malicious files—including PHP scripts—to the server's uploads directory. If the web server is configured to execute PHP files from that directory, an attacker could achieve remote code execution.

  • CVE-2026-10303HIGH 7.4

    ServerCo's getssl tool versions 2.49 and earlier fail to properly validate ACME challenge tokens received from certificate authorities. This allows an attacker positioned on the network path to the CA, or operating a malicious CA endpoint, to inject specially crafted tokens that manipulate which files getssl writes to during certificate validation. Because getssl often runs with elevated privileges, a successful exploit can lead to unauthorized file creation or modification on the system, and in some cases, execution of arbitrary commands.

  • CVE-2026-10694HIGH 7.3

    SourceCodester's Online Food Ordering System version 2.0 contains a file inclusion vulnerability in its index.php page parameter. An unauthenticated attacker can supply a malicious page argument to cause the application to include and execute arbitrary files, potentially from the local filesystem or remote sources. This vulnerability requires no user interaction and can be exploited over the network. Public exploits are available.

  • CVE-2025-52465HIGH 7.2

    GeoServer, an open-source geospatial data server, contains a vulnerability that allows authenticated administrators to write the master password to arbitrary files on the server. An attacker with admin credentials can navigate to the Master Password Dump page and specify an absolute file path to dump the plaintext master password, potentially exposing it to unauthorized access or further compromise. This requires the attacker already have administrative access and the target file path must not exist, but the vulnerability significantly reduces the security of GeoServer's most sensitive credential.

  • CVE-2026-55477HIGH 7.2

    3X-UI, a web-based control panel for managing Xray-core proxy servers, contains a vulnerability in its database import feature that allows authenticated administrators to write arbitrary files to the server. An attacker with admin credentials can manipulate Xray configuration values during import to place malicious files on disk, potentially leading to code execution with the privileges of the Xray process—which may be root. The vulnerability affects all versions prior to 3.3.1 and is resolved in that release.

  • CVE-2026-47214HIGH 7.1

    Docling, a document processing library that converts various file formats and integrates with AI systems, contains a vulnerability in its HTML parser that mishandles URIs and file paths. An attacker can exploit this by crafting a malicious document that, when processed by a user, could leak sensitive information or cause the application to become unavailable. The vulnerability affects versions prior to 2.94.0 and requires user interaction to trigger.

  • CVE-2026-53915HIGH 7.1

    JetBrains GoLand before version 2026.1.3 contains a remote code execution vulnerability triggered when developers open untrusted project configurations. An attacker can craft a malicious project file that executes arbitrary code on a developer's machine without requiring any special permissions or complex user interaction beyond opening the project. This affects GoLand across all network environments.

  • CVE-2026-55700HIGH 7.1

    pnpm, a widely-used JavaScript package manager, contains a path traversal vulnerability in its download staging feature that could allow an attacker to overwrite files outside the intended download directory. By crafting a malicious package manifest with specially designed name and version fields, an attacker could trick pnpm into writing files to unintended locations on a developer's machine. This affects versions 11.3.0 through 11.5.2. The fix validates and sanitizes both the package name and version before deriving a safe filename, then verifies the destination path before writing any files.

  • CVE-2026-59194HIGH 7.1

    pnpm, a widely-used Node.js package manager, contains a path traversal vulnerability in its patch-removal functionality. An attacker can craft a malicious patch entry that points outside the intended patches directory, allowing deletion of arbitrary files accessible to the user running pnpm. This occurs when using the `pnpm patch-remove` command with a compromised or attacker-controlled patch configuration. The vulnerability affects versions before 10.34.4 and 11.7.0.

  • CVE-2026-59196HIGH 7.1

    pnpm, a widely-used Node.js package manager, contains a lockfile parsing vulnerability that allows a specially crafted lockfile to create directory traversal or reserved directory overwrites. An attacker who controls a lockfile (via a malicious package, compromised repository, or supply chain attack) can manipulate how pnpm installs dependencies, potentially writing files to unexpected locations or overwriting critical pnpm internal directories. The vulnerability requires user interaction—specifically, running pnpm on a malicious lockfile—but no authentication is required. Versions prior to 10.34.4 and 11.7.0 are affected.

  • CVE-2026-59807MEDIUM 6.8

    Composio SDK versions before 0.2.32-beta.283 contain a flaw that bypasses file path validation controls. An attacker can craft malicious prompts that trick the SDK into reading and uploading sensitive files—such as SSH private keys and credentials—to attacker-controlled storage. The vulnerability requires network access but does not need authentication or user interaction, making it a meaningful risk for environments where the SDK processes untrusted input.

  • CVE-2026-46397MEDIUM 6.5

    HAX CMS, a content management system for building microsite networks, contains a flaw that lets authenticated users read files they shouldn't have access to. An attacker with a valid login (even a low-privilege account) can manipulate how the system saves site configuration data, causing it to expose sensitive files like system passwords, API keys, or database credentials stored on the web server. This is a classic file inclusion attack that works over the network without requiring special browser interaction. The vendor has patched this in version 26.0.0.

  • CVE-2026-55699MEDIUM 6.5

    pnpm, a widely-used Node.js package manager, contains a path-traversal vulnerability in how it handles global package installation and removal. Specifically, malicious package manifests can specify bin names (executable entry points) that bypass pnpm's validation checks—using names like ".", "..", or empty strings. When a user installs such a package globally and later removes, updates, or adds a replacement, pnpm incorrectly derives these malicious bin names and attempts to delete files at unintended locations. A bin name of "." would target the entire global bin directory; ".." would target its parent directory. An attacker distributing a malicious package could potentially delete or corrupt critical files in the global bin environment on a user's system.

  • CVE-2026-8118MEDIUM 6.5

    Royal Addons for Elementor, a WordPress plugin for building pages with Elementor, has a file-reading flaw affecting versions 1.7.1058 and 1.7.1059. When handling CSV file uploads in data table widgets, the plugin fails to properly validate file paths. An authenticated user with Contributor-level permission or higher can exploit this to read any file on the server that the PHP process can access—including sensitive configuration files like wp-config.php containing database credentials. The vulnerability stems from a fallback mechanism in a helper function that was added to patch a previous security issue.

  • CVE-2026-10558MEDIUM 6.3

    SourceCodester Pizzafy Ecommerce System version 1.0 contains a file inclusion vulnerability in its administrative interface. An attacker with valid login credentials can manipulate the 'page' parameter in /admin/index.php to include and execute arbitrary files on the server. This allows an authenticated attacker to read sensitive files, modify system behavior, or potentially execute code. The vulnerability is publicly known and proof-of-concept code is available.

  • CVE-2026-10559MEDIUM 6.3

    SourceCodester Pizzafy Ecommerce System version 1.0 contains a file inclusion vulnerability in its index.php file. An authenticated attacker can manipulate the 'page' parameter to include arbitrary files, potentially exposing sensitive data or executing unintended code. The vulnerability requires valid credentials but can be exploited over the network without user interaction.

  • CVE-2026-13748MEDIUM 6.3

    Snowflake CLI versions before 3.19 contain a path traversal flaw that allows attackers to read arbitrary files from the local system. If an attacker can trick a user into processing malicious project or repository content, the CLI will read files outside the intended project directory and send their contents to Snowflake services. The attacker would then need to access the victim's Snowflake account—such as through query history or uploaded files—to retrieve the exfiltrated data. This requires user interaction and depends on the attacker having follow-on access to the Snowflake environment.

  • CVE-2026-20175MEDIUM 6.1

    A remote attacker can trick a user into clicking a malicious link that causes their browser to load files from an attacker-controlled location while interacting with Cisco Finesse. Because the application doesn't properly validate where those files come from, an attacker can inject malicious scripts or steal sensitive information visible in the user's active session—all without needing to authenticate first.

  • CVE-2026-48520MEDIUM 6.1

    Langflow, a platform for building AI workflows and agents, has a file-read vulnerability in its "Shareable Playground" feature that allows public access to the flow. When a flow is made public, an attacker can craft execution requests that cause Langflow to read arbitrary files from the system—either local files or cloud storage like S3—and feed their contents into the LLM. This exposure depends on how the flow is configured and what storage backends are enabled. The vulnerability is patched in version 1.10.0.

  • CVE-2026-2604MEDIUM 5.6

    A vulnerability in evolution-data-server allows a Flatpak application with D-Bus access to delete arbitrary files on the host system. The flaw stems from inconsistent validation logic: when contacts are created or modified, malicious URIs containing directory traversal sequences (like "../") are accepted without proper checks. When those contacts are later deleted, a less strict validation routine processes the URI and actually follows the traversal, deleting files the attacker specified. This could affect critical system files, including Flatpak override configurations that control sandboxing rules.

  • CVE-2026-12480MEDIUM 5.5

    Keras, a popular deep learning library, contains a flaw that allows attackers to read files from a victim's computer by crafting malicious model files. The vulnerability exists because Keras doesn't properly validate certain types of datasets when loading `.keras` or `.h5` model files. An attacker can create a specially crafted model that, when loaded by a user, silently reads sensitive files from the filesystem without the user's knowledge. This is a regression—a previously patched vulnerability was incompletely fixed, leaving the door open to the same attack vector.

  • CVE-2026-55628MEDIUM 5.5

    ImageMagick's `-concatenate` operation fails to enforce security policies that restrict file access, allowing users to read and write files outside approved paths. This vulnerability affects ImageMagick versions prior to 7.1.2-26 and requires user interaction to exploit—an attacker would need to trick someone into running a specially crafted ImageMagick command. The issue has been resolved in version 7.1.2-26 and later.

  • CVE-2026-41412MEDIUM 4.9

    alf.io is an open-source ticketing platform used by conferences and events to manage reservations. The vulnerability lies in how alf.io sandboxes custom extensions (plugins) that users can write to extend functionality. The sandbox was designed to safely run untrusted extension code, but it failed to protect file access. Specifically, extensions have access to an HTTP client tool that includes a method for uploading files. This method does not validate or restrict which files can be read—a malicious extension can read any file that the alf.io application has permission to access on the server, then send that file's contents to an attacker's server. An attacker would need to either write a malicious extension or trick an administrator into installing one, but once active, the extension can quietly exfiltrate sensitive data like configuration files, database credentials, or user records.

  • CVE-2026-59819MEDIUM 4.9

    LiteLLM, a proxy server used to standardize API calls to large language models, contains a vulnerability in its connection testing endpoint that allows authorized administrators to read sensitive files from the server's filesystem. An attacker with legitimate access to the `/health/test_connection` API could craft requests that reference local files via OIDC configuration parameters, effectively bypassing normal file access restrictions. This affects versions before 1.83.10-stable and is particularly concerning in shared or multi-tenant environments where proxy administration privileges may be distributed.

  • CVE-2026-3602MEDIUM 4.7

    IBM App Connect Enterprise and Integration Bus contain a SQL injection vulnerability that could allow a remote attacker to trick users into inadvertently creating files on their systems. While the attack requires user interaction and operates with local system access constraints, successful exploitation could result in unauthorized file creation or modification. The vulnerability affects multiple versions across IBM's integration middleware stack.

  • CVE-2025-12656LOW 3.8

    The WPvivid Backup & Migration plugin for WordPress contains a vulnerability that allows administrators to inadvertently (or maliciously) delete arbitrary directories from the server. The flaw lies in insufficient validation of file paths when canceling a staging site, meaning an authenticated admin could specify any folder path and have it removed. This is restricted to high-privilege accounts, but the impact—permanent data loss—is serious for affected organizations.

  • CVE-2026-49358LOW 3.0

    PhpWeasyPrint, a PHP library used to generate PDFs from URLs or HTML content, contains a flaw in how it manages temporary files. Before version 2.6.0, the list of temporary files is stored in a public variable that any code in the application can modify. When the library shuts down, it deletes every file listed in that variable without checking whether those files actually belong to the temporary folder. This means an attacker with code execution could trick the library into deleting arbitrary files on the system by adding them to the list. The vulnerability requires an attacker to have already compromised the application or have another way to run PHP code in the same process.