CWE-59— Improper Link Resolution Before File Access (Link Following)
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.— MITRE CWE catalog
1,746 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-59page 14 of 35
- CVE-2020-29529HIGHCVSS 7.5EG 7.52020-12-03
HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protections could be bypassed with specific constructions of multiple symlinks. Fixed in 0.5.0.
- CVE-2020-7282HIGHCVSS 7.5EG 7.52020-07-03
Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an uni…
- CVE-2019-19695HIGHCVSS 7.5EG 7.52019-12-24
A privilege escalation vulnerability in Trend Micro Antivirus for Mac 2019 (v9.0.1379 and below) could potentially allow an attacker to create a symbolic link to a target file and modify it.
- CVE-2019-8463HIGHCVSS 7.5EG 7.52019-12-23
A denial of service vulnerability was reported in Check Point Endpoint Security Client for Windows before E82.10, that could allow service log file to be written to non-standard locations.
- CVE-2013-4655HIGHCVSS 7.5EG 7.52019-11-13
Symlink Traversal vulnerability in Belkin N900 due to misconfiguration in the SMB service.
- CVE-2013-1809HIGHCVSS 7.5EG 7.52019-11-07
Gambas before 3.4.0 allows remote attackers to move or manipulate directory contents or perform symlink attacks due to the creation of insecure temporary directories.
- CVE-2012-2945HIGHCVSS 7.5EG 7.52019-10-29
Hadoop 1.0.3 contains a symlink vulnerability.
- CVE-2018-20990HIGHCVSS 7.5EG 7.52019-08-26
An issue was discovered in the tar crate before 0.4.16 for Rust. Arbitrary file overwrite can occur via a symlink or hardlink in a TAR archive.
- CVE-2019-1188HIGHCVSS 7.5EG 7.52019-08-14
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed. An attacker who successfully exploited this vulnerability could gain the same user rights as the local us…
- CVE-2019-13915HIGHCVSS 7.5EG 7.52019-07-18
b3log Wide before 1.6.0 allows three types of attacks to access arbitrary files. First, the attacker can write code in the editor, and compile and run it approximately three times to read an arbitrary file. Second, the attacker can create …
- CVE-2019-13173HIGHCVSS 7.5EG 7.52019-07-02
fstream before 1.0.12 is vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system, and a file that matches the hardlink, will overwrite the system's file with the content…
- CVE-2019-12209HIGHCVSS 7.5EG 7.52019-06-04
Yubico pam-u2f 1.0.7 attempts parsing of the configured authfile (default $HOME/.config/Yubico/u2f_keys) as root (unless openasuser was enabled), and does not properly verify that the path lacks symlinks pointing to other files on the syst…
- CVE-2018-20834HIGHCVSS 7.5EG 7.52019-04-30
A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with…
- CVE-2019-11503HIGHCVSS 7.5EG 7.52019-04-24
snap-confine as included in snapd before 2.39 did not guard against symlink races when performing the chdir() to the current working directory of the calling user, aka a "cwd restore permission bypass."
- CVE-2019-11502HIGHCVSS 7.5EG 7.52019-04-24
snap-confine in snapd before 2.38 incorrectly set the ownership of a snap application to the uid and gid of the first calling user. Consequently, that user had unintended access to a private /tmp directory.
- CVE-2018-17567HIGHCVSS 7.5EG 7.52018-09-28
Jekyll through 3.6.2, 3.7.x through 3.7.3, and 3.8.x through 3.8.3 allows attackers to access arbitrary files by specifying a symlink in the "include" key in the "_config.yml" file.
- CVE-2011-2765HIGHCVSS 7.5EG 7.52018-08-20
pyro before 3.15 unsafely handles pid files in temporary directory locations and opening the pid file as root. An attacker can use this flaw to overwrite arbitrary files via symlinks.
- CVE-2018-11637HIGHCVSS 7.5EG 7.52018-07-03
Information leakage vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to read arbitrary files from the /var/ directory because a symlink exists under the web root.
- CVE-2018-12015HIGHCVSS 7.5EG 7.52018-06-07
In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.
- CVE-2018-1000073HIGHCVSS 7.5EG 7.52018-03-13
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Directory Traversal vulnerability in …
- CVE-2017-2619HIGHCVSS 7.5EG 7.52018-03-12
Samba before versions 4.6.1, 4.5.7 and 4.4.11 are vulnerable to a malicious client using a symlink race to allow access to areas of the server file system not exported under the share definition.
- CVE-2017-1000420HIGHCVSS 7.5EG 7.52018-01-02
Syncthing version 0.14.33 and older is vulnerable to symlink traversal resulting in arbitrary file overwrite
- CVE-2017-1000115HIGHCVSS 7.5EG 7.52017-10-05
Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the repository
- CVE-2015-5705HIGHCVSS 7.5EG 7.52017-09-06
Argument injection vulnerability in devscripts before 2.15.7 allows remote attackers to write to arbitrary files via a crafted symlink and crafted filename.
- CVE-2015-8860HIGHCVSS 7.5EG 7.52017-01-23
The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an archive.
- CVE-2002-2323HIGHCVSS 7.5EG 7.52002-12-31
Sun PC NetLink 1.0 through 1.2 does not properly set the access control list (ACL) for files and directories that use symbolic links and have been restored from backup, which could allow local or remote attackers to bypass intended access …
- CVE-2001-1042HIGHCVSS 7.5EG 7.52001-07-02
Transsoft Broker 5.9.5.0 allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file that points to the target file.
- CVE-2001-1043HIGHCVSS 7.5EG 7.52001-07-01
ArGoSoft FTP Server 1.2.2.2 allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file that points to the target file.
- CVE-2001-1386HIGHCVSS 7.5EG 7.52001-07-01
WFTPD 3.00 allows remote attackers to read arbitrary files by uploading a (link) file that ends in a ".lnk." extension, which bypasses WFTPD's check for a ".lnk" extension.
- CVE-2000-0342HIGHCVSS 7.5EG 7.52000-04-28
Eudora 4.x allows remote attackers to bypass the user warning for executable attachments such as .exe, .com, and .bat by using a .lnk file that refers to the attachment, aka "Stealth Attachment."
- CVE-2025-69429HIGHCVSS 6.1EG 7.52026-02-03
The ORICO NAS CD3510 (version V1.9.12 and below) contains an Incorrect Symlink Follow vulnerability that could be exploited by attackers to leak or tamper with the internal file system. Attackers can format a USB drive to ext4, create a sy…
- CVE-2024-44211HIGHCVSS 5.5EG 7.52024-12-20
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be able to access user-sensitive data.
- CVE-2017-5188HIGHCVSS 5.0EG 7.52018-03-01
The bs_worker code in open build service before 20170320 followed relative symlinks, allowing reading of files outside of the package source directory during build, allowing leakage of private information.
- CVE-2013-0927HIGHCVSS v2 7.5EG 7.52013-04-10
Google Chrome OS before 26.0.1410.57 relies on a Pango pango-utils.c read_config implementation that loads the contents of the .pangorc file in the user's home directory, and the file referenced by the PANGO_RC_FILE environment variable, w…
- CVE-2008-0870HIGHCVSS v2 7.5EG 7.52008-02-21
BEA WebLogic Portal 10.0 and 9.2 through Maintenance Pack 2, under certain circumstances, can redirect a user from the https:// URI for the Portal Administration Console to an http URI, which allows remote attackers to sniff the session.
- CVE-2026-53793HIGHCVSS 7.4EG 7.42026-08-13
rsync before 3.5.0 contains a path confinement bypass vulnerability that allows remote clients to escape the intended inner-module root confinement by constructing paths that resolve outside the chroot boundary when the module root contai…
- CVE-2026-57991HIGHCVSS 7.4EG 7.42026-07-03
Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
- CVE-2026-45539HIGHCVSS 7.4EG 7.42026-05-15
Microsoft APM is an open-source, community-driven dependency manager for AI agents. From 0.5.4 to 0.12.4, two primitive integrators in apm-cli enumerate package files with bare Path.glob() / Path.rglob() calls and read each match with Path…
- CVE-2026-41882HIGHCVSS 7.4EG 7.42026-04-30
In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server
- CVE-2025-63946HIGHCVSS 7.4EG 7.42026-02-23
A privilege escalation (PE) vulnerability in the Tencent PC Manager app thru 17.10.28554.205 on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to s…
- CVE-2025-63945HIGHCVSS 7.4EG 7.42026-02-23
A privilege escalation (PE) vulnerability in the Tencent iOA app thru 210.9.28693.621001 on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to succe…
- CVE-2020-6012HIGHCVSS 7.4EG 7.42020-08-04
ZoneAlarm Anti-Ransomware before version 1.0.713 copies files for the report from a directory with low privileges. A sophisticated timed attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on…
- CVE-2017-15357HIGHCVSS 7.4EG 7.42017-12-01
The setpermissions function in the auto-updater in Arq before 5.9.7 for Mac allows local users to gain root privileges via a symlink attack on the updater binary itself.
- CVE-2026-107716HIGHCVSS 7.3EG 7.32026-10-08
Banks generates meaningful LLM prompts using a simple template language. Prior to 2.5.1, Banks DirectoryPromptRegistry does not reject symbolic links for index.json or discovered and existing .jinja prompt files. In an application where un…
- CVE-2026-81690HIGHCVSS 7.3EG 7.32026-08-27
openssl-encrypt (pip package) before 1.4.9 contains a symlink-following flaw in its verify-usb v2 added-file allowlist scan. The scan enumerated the drive with rglob(), which in CPython does not descend into symlinked directories and treat…
- CVE-2026-50364HIGHCVSS 7.3EG 7.32026-07-14
Improper link resolution before file access ('link following') in Windows Server Backup allows an authorized attacker to elevate privileges locally.
- CVE-2026-15684HIGHCVSS 7.3EG 7.32026-07-13
Glarysoft Glary Utilities Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Glarysoft Glary Utilities. An attacker must first obtain the a…
- CVE-2026-11837HIGHCVSS 7.3EG 7.32026-06-10
A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() instead of os.lchown() and opens files without O_NOFOLLOW when managing SSH authorized keys. A…
- CVE-2025-12838HIGHCVSS 7.3EG 7.32025-12-23
MSP360 Free Backup Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MSP360 Free Backup. An attacker must first obtain the ability to exec…
- CVE-2025-46637HIGHCVSS 7.3EG 7.32025-12-09
Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A local malicious user could potentially exploit this vulnerability, leading to Elevation of privileges.
Map vulnerabilities like CWE-59 to your infrastructure
EchelonGraph correlates every CVE — across CWE-59 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →