Skip to main content

About CWE-73

The application may read, overwrite or execute unexpected files. Availability can suffer if the path points to a large file, a special device or a file with an unexpected format.

MITRE name
External Control of File Name or Path
Abstraction
Base: abstract, but detailed enough to infer detection and prevention methods
Status
Draft

Mitigations

  • +Map a fixed set of input values, such as numeric IDs, to actual filenames and reject all other input.
  • +Run the code in a sandbox or jail that restricts file access to one directory.
  • +Validate filenames with a strict character allowlist and a list of permitted extensions.
  • +Repeat client-side checks on the server.

Detection
Automated static analysis that models data flow can often detect external control of filenames, though it may report false positives where validation exists.

CWE-73 Vulnerabilities

8 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2025-33053
Internet Shortcut Files Remote Code Execution Vulnerability
Microsoft8.887.0%KEV2025-06-10
CVE-2025-24054
NTLM Hash Disclosure Spoofing Vulnerability
Microsoft6.558.9%KEV2025-03-11
CVE-2025-0111
PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface
Palo Alto Networks7.12.0%KEV2025-02-12
CVE-2024-43451
NTLM Hash Disclosure Spoofing Vulnerability
Microsoft6.584.1%KEV2024-11-12
CVE-2020-1631
Out of Cycle Security Advisory: Junos OS: Security vulnerability in J-Web and web based (HTTP/HTTPS) services
Juniper Networks8.84.8%KEV2020-05-04
CVE-2026-20872
NTLM Hash Disclosure Spoofing Vulnerability
Microsoft6.520.1%2026-01-13
CVE-2026-20925
NTLM Hash Disclosure Spoofing Vulnerability
Microsoft6.518.2%2026-01-13
CVE-2026-21249
Windows NTLM Spoofing Vulnerability
Microsoft3.311.5%2026-02-10

Most Affected Vendors

Frequently Asked Questions

What is CWE-73?→

CWE-73 is external control of a file name or path. Outside input decides which file the product reads, writes or runs.

How is CWE-73 different from path traversal?→

CWE-73 covers any outside influence over filenames or paths. Path traversal (CWE-22) is the specific case of escaping a restricted directory.

How many exploited vulnerabilities are classified as CWE-73?→

This database lists 8 CVE records mapped to CWE-73 by their CVE Numbering Authority. 5 of them are in the CISA Known Exploited Vulnerabilities catalog. Examples include CVE-2025-33053, CVE-2025-24054, CVE-2025-0111.

Sources

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.