目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CWE-73 文件名或路径的外部可控制 类漏洞列表 482

CWE-73 文件名或路径的外部可控制 类弱点 482 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-73 属于路径遍历漏洞,指应用程序允许用户输入控制文件系统操作中的文件名或路径。攻击者通常利用此缺陷构造恶意路径,以访问或修改系统关键文件及敏感数据,从而破坏应用完整性。开发者应避免直接拼接用户输入,需通过白名单验证、规范化路径及严格过滤特殊字符,确保最终路径位于预期的安全目录内,从而有效阻断非法访问。

MITRE CWE 官方描述
CWE:CWE-73 外部控制文件名或路径 (External Control of File Name or Path) 英文:产品允许用户输入控制或影响在文件系统操作 (filesystem operations) 中使用的路径或文件名。 这可能导致攻击者访问或修改对应用程序至关重要的系统文件或其他文件。路径操纵错误 (Path manipulation errors) 在满足以下两个条件时发生:1. 攻击者可以指定在文件系统操作 (operation on the filesystem) 中使用的路径。2. 通过指定资源,攻击者获得了原本不被允许的能力。例如,程序可能赋予攻击者覆盖指定文件或运行由攻击者控制的配置的能力。
常见影响 (3)
Integrity, Confidentiality Read Files or Directories, Modify Files or Directories
The application can operate on unexpected files. Confidentiality is violated when the targeted filename is not directly readable by the attacker.
Integrity, Confidentiality, Availability Modify Files or Directories, Execute Unauthorized Code or Commands
The application can operate on unexpected files. This may violate integrity if the filename is written to, or if the filename is for a program or other form of executable code.
Availability DoS: Crash, Exit, or Restart, DoS: Resource Consumption (Other)
The application can operate on unexpected files. Availability can be violated if the attacker specifies an unexpected file that the application modifies. Availability can also be affected if the attacker specifies a filename for a large file, or points to a special device or a file that does not hav…
缓解措施 (5)
Architecture and Design When the set of filenames is limited or known, create a mapping from a set of fixed input values (such as numeric IDs) to the actual filenames, and reject all other inputs. For example, ID 1 could map to "inbox.txt" and ID 2 could map to "profile.txt". Features such as the ESAPI AccessReferenceMap provide this capability.
Architecture and Design, Operation Run your code in a "jail" or similar sandbox environment that enforces strict boundaries between the process and the operating system. This may effectively restrict all access to files within a particular directory. Examples include the Unix chroot jail and AppArmor. In general, managed code may provide some protection. This may not be a feasible solution, and it only limits the impact to the oper…
Architecture and Design For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-side checks entirely. Then, these modified values would be submitted to the server.
Implementation Assume all input is malicious. Use an "accept known good" input validation strategy, i.e., use a list of acceptable inputs that strictly conform to specifications. Reject any input that does not strictly conform to specifications, or transform it into something that does. When performing input validation, consider all potentially relevant properties, including length, type of input, the full range…
Effectiveness: High
Implementation Use a built-in path canonicalization function (such as realpath() in C) that produces the canonical version of the pathname, which effectively removes ".." sequences and symbolic links (CWE-23, CWE-59).
代码示例 (2)
The following code uses input from an HTTP request to create a file name. The programmer has not considered the possibility that an attacker could provide a file name such as "../../tomcat/conf/server.xml", which causes the application to delete one of its own configuration files (CWE-22).
String rName = request.getParameter("reportName"); File rFile = new File("/usr/local/apfr/reports/" + rName); ... rFile.delete();
Bad · Java
The following code uses input from a configuration file to determine which file to open and echo back to the user. If the program runs with privileges and malicious users can change the configuration file, they can use the program to read any file on the system that ends with the extension .txt.
fis = new FileInputStream(cfg.getProperty("sub")+".txt"); amt = fis.read(arr); out.println(arr);
Bad · Java
CVE ID 标题 CVSS 风险等级 Published
CVE-2026-18806 TÜBİTAK BİLGEM pardus-image-writer 输入验证错误漏洞 — pardus-image-writer 7.1 High 2026-08-04
CVE-2026-65802 Microsoft Edge 输入验证错误漏洞 — Microsoft Edge (Chromium-based) 7.4 High 2026-08-03
CVE-2026-66310 Microsoft Edge 输入验证错误漏洞 — Microsoft Edge for Android 7.7 High 2026-08-03
CVE-2026-64816 RapidRAW <1.6.0 路径变量NTLMv2凭据泄露漏洞 — RapidRAW 6.5 Medium 2026-07-30
CVE-2026-56390 GNU Bison 输入验证错误漏洞 — Bison 4.6 Medium 2026-07-29
CVE-2026-57916 proCertum SmartSign CPS URI任意路径执行漏洞 — proCertum SmartSign 4.6 Medium 2026-07-27
CVE-2026-65896 Grav 输入验证错误漏洞 — grav 7.1 High 2026-07-23
CVE-2026-45139 CI4MS 输入验证错误漏洞 — ci4ms 6.5 Medium 2026-07-20
CVE-2026-50162 oras-project oras-go 输入验证错误漏洞 — oras-go - - 2026-07-17
CVE-2026-9587 Sangoma Switchvox SMB Edition 输入验证错误漏洞 — Switchvox SMB Edition - - 2026-07-17
CVE-2026-44019 docling-project docling-core 资源管理错误漏洞 — docling-core 8.1 High 2026-07-16
CVE-2026-50148 Metabase 输入验证错误漏洞 — metabase 10.0 Critical 2026-07-15
CVE-2026-61873 getgrav Grav 输入验证错误漏洞 — grav 8.1 High 2026-07-15
CVE-2026-50462 Microsoft Windows Ancillary Function Driver for WinSock 输入验证错误漏洞 — Windows 10 Version 1607 7.8 High 2026-07-14
CVE-2026-54108 Microsoft Office Sharepoint Server 输入验证错误漏洞 — Microsoft SharePoint Enterprise Server 2016 6.5 Medium 2026-07-14
CVE-2026-55002 Microsoft SQL Server 输入验证错误漏洞 — Microsoft SQL Server 2016 Service Pack 3 (GDR) 8.8 High 2026-07-14
CVE-2026-61462 zereight GitLab MCP Server 输入验证错误漏洞 — mcp-gitlab 8.6 High 2026-07-13
CVE-2026-14480 Autonomy OpenPLC Runtime 输入验证错误漏洞 — OpenPLC 9.9 Critical 2026-07-10
CVE-2026-53449 Coturn 输入验证错误漏洞 — coturn 6.0 Medium 2026-07-10
CVE-2026-59793 JetBrains TeamCity 输入验证错误漏洞 — TeamCity 8.8 High 2026-07-10
CVE-2026-59807 Composio 输入验证错误漏洞 — composio 6.8 Medium 2026-07-08
CVE-2026-59819 LiteLLM 输入验证错误漏洞 — litellm - - 2026-07-08
CVE-2026-49145 PETDANCE App::Ack 权限许可和访问控制问题漏洞 — App::Ack - - 2026-07-08
CVE-2026-6101 Mohammed Kaludi AMP for WP 输入验证错误漏洞 — AMP for WP – Accelerated Mobile Pages 7.5 High 2026-07-07
CVE-2026-53648 FOSSBilling 权限许可和访问控制问题漏洞 — FOSSBilling - - 2026-07-06
CVE-2026-58293 Microsoft Edge 输入验证错误漏洞 — Microsoft Edge (Chromium-based) 8.1 High 2026-07-03
CVE-2026-8921 ASUS Business Manager 输入验证错误漏洞 — ASUS Business Manager 8.5 High 2026-07-03
CVE-2026-5821 Elementor Image Optimizer – Optimize Images and Convert to WebP or AVIF 输入验证错误漏洞 — Image Optimizer – Optimize Images and Convert to WebP or AVIF 8.1 High 2026-07-02
CVE-2026-55628 ImageMagick 输入验证错误漏洞 — ImageMagick 5.5 Medium 2026-07-01
CVE-2026-12480 keras 输入验证错误漏洞 — keras-team/keras - - 2026-07-01

CWE-73(文件名或路径的外部可控制) 是常见的弱点类别,本平台收录该类弱点关联的 482 条 CVE 漏洞。