External Control of File Name or Path (CWE-73)
CWE-73 occurs when user input controls or influences file names or paths used in filesystem operations. MITRE frames it as two conditions together: an attacker can specify the path, and doing so grants a capability that would not otherwise be allowed. It often begins chains with other file-related weaknesses.
About CWE-73
The application may read, overwrite or execute unexpected files. Availability can suffer if the path points to a large file, a special device or a file with an unexpected format.
Mitigations
- +Map a fixed set of input values, such as numeric IDs, to actual filenames and reject all other input.
- +Run the code in a sandbox or jail that restricts file access to one directory.
- +Validate filenames with a strict character allowlist and a list of permitted extensions.
- +Repeat client-side checks on the server.
Detection
Automated static analysis that models data flow can often detect external control of filenames, though it may report false positives where validation exists.
CWE-73 Vulnerabilities
8 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2025-33053 | Internet Shortcut Files Remote Code Execution Vulnerability | Microsoft | 8.8 | 87.0% | KEV | 2025-06-10 |
| CVE-2025-24054 | NTLM Hash Disclosure Spoofing Vulnerability | Microsoft | 6.5 | 58.9% | KEV | 2025-03-11 |
| CVE-2025-0111 | PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface | Palo Alto Networks | 7.1 | 2.0% | KEV | 2025-02-12 |
| CVE-2024-43451 | NTLM Hash Disclosure Spoofing Vulnerability | Microsoft | 6.5 | 84.1% | KEV | 2024-11-12 |
| CVE-2020-1631 | Out of Cycle Security Advisory: Junos OS: Security vulnerability in J-Web and web based (HTTP/HTTPS) services | Juniper Networks | 8.8 | 4.8% | KEV | 2020-05-04 |
| CVE-2026-20872 | NTLM Hash Disclosure Spoofing Vulnerability | Microsoft | 6.5 | 20.1% | 2026-01-13 | |
| CVE-2026-20925 | NTLM Hash Disclosure Spoofing Vulnerability | Microsoft | 6.5 | 18.2% | 2026-01-13 | |
| CVE-2026-21249 | Windows NTLM Spoofing Vulnerability | Microsoft | 3.3 | 11.5% | 2026-02-10 |
Most Affected Vendors
Tool Categories That Address This Weakness
Frequently Asked Questions
What is CWE-73?→
CWE-73 is external control of a file name or path. Outside input decides which file the product reads, writes or runs.
How is CWE-73 different from path traversal?→
CWE-73 covers any outside influence over filenames or paths. Path traversal (CWE-22) is the specific case of escaping a restricted directory.
How many exploited vulnerabilities are classified as CWE-73?→
This database lists 8 CVE records mapped to CWE-73 by their CVE Numbering Authority. 5 of them are in the CISA Known Exploited Vulnerabilities catalog. Examples include CVE-2025-33053, CVE-2025-24054, CVE-2025-0111.
Sources
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.