CWE•Base•Draft•20 recent CVEs
CWE-427Uncontrolled Search Path Element
Description
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
[object Object]
Common consequences
- Confidentiality,Integrity,Availability→Execute Unauthorized Code or Commands
Potential mitigations
- Architecture and Design,ImplementationHard-code the search path to a set of known-safe values (such as system directories), or only allow them to be specified by the administrator in a configuration file. Do not allow these settings to be modified by an external party. Be careful to avoid related weaknesses such as CWE-426 and CWE-428.
- ImplementationWhen invoking other programs, specify those programs using fully-qualified pathnames. While this is an effective approach, code that uses fully-qualified pathnames might not be portable to other systems that do not use the same pathnames. The portability can be improved by locating the full-qualified paths in a centralized, easily-modifiable location within the source code, and having the code ref
- ImplementationRemove or restrict all environment settings before invoking other programs. This includes the PATH environment variable, LD_LIBRARY_PATH, and other settings that identify the location of code libraries, and any application-specific search paths.
- ImplementationCheck your search path before use and remove any elements that are likely to be unsafe, such as the current working directory or a temporary files directory. Since this is a denylist approach, it might not be a complete solution.
- ImplementationUse other functions that require explicit paths. Making use of any of the other readily available functions that require explicit paths is a safe way to avoid this problem. For example, system() in C does not require a full path since the shell can take care of finding the program using the PATH environment variable, while execl() and execv() require a full path.
Related CWEs
Recent CVEs classified under this CWE
CVE-2026-875308.12026-09-09CVE-2026-761998.62026-09-08CVE-2026-729804.42026-09-08CVE-2026-69587.82026-09-04CVE-2026-452217.82026-09-01CVE-2026-195907.32026-09-01CVE-2026-826492026-08-30CVE-2026-650939.92026-08-25CVE-2026-550155.52026-08-20CVE-2026-550137.12026-08-20CVE-2026-597812026-08-18CVE-2026-507737.82026-08-17CVE-2026-560907.32026-08-17CVE-2026-02947.82026-08-13CVE-2026-168609.92026-08-12CVE-2025-545122026-08-11CVE-2026-341752026-08-11CVE-2026-327882026-08-11CVE-2026-287002026-08-11CVE-2025-80872026-08-11