Common Weakness Enumeration

    CWE Definition / CWE-73

    CWE-73: External Control of File Name or Path

    The product allows user input to control or influence paths or file names that are used in filesystem operations.

    Published:19 Jul 2006
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-642: External Control of Critical State Data

    CWE-610: Externally Controlled Reference to a Resource in Another Sphere

    CWE-20: Improper Input Validation

    CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    CWE-41: Improper Resolution of Path Equivalence

    CWE-98: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

    CWE-434: Unrestricted Upload of File with Dangerous Type

    CWE-59: Improper Link Resolution Before File Access ('Link Following')