CWE-59— Improper Link Resolution Before File Access (Link Following)
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.— MITRE CWE catalog
1,746 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-59page 16 of 35
- CVE-2008-4474HIGHCVSS v2 7.2EG 7.22008-10-07
freeradius-dialupadmin in freeradius 2.0.4 allows local users to overwrite arbitrary files via a symlink attack on temporary files in (1) backup_radacct, (2) clean_radacct, (3) monthly_tot_stats, (4) tot_stats, and (5) truncate_radacct.
- CVE-2008-4440HIGHCVSS v2 7.2EG 7.22008-10-03
The to-upgrade plugin in feta 1.4.16 allows local users to overwrite arbitrary files via a symlink on the (1) /tmp/feta.install.$USER and (2) /tmp/feta.avail.$USER temporary files.
- CVE-2008-4406HIGHCVSS v2 7.2EG 7.22008-10-03
A certain Debian patch to the run scripts for sabre (aka xsabre) 0.2.4b allows local users to delete or overwrite arbitrary files via a symlink attack on unspecified .tmp files.
- CVE-2008-3521HIGHCVSS v2 7.2EG 7.22008-10-02
Race condition in the jas_stream_tmpfile function in libjasper/base/jas_stream.c in JasPer 1.900.1 allows local users to cause a denial of service (program exit) by creating the appropriate tmp.XXXXXXXXXX temporary file, which causes Jaspe…
- CVE-2008-4108HIGHCVSS v2 7.2EG 7.22008-09-18
Tools/faqwiz/move-faqwiz.sh (aka the generic FAQ wizard moving tool) in Python 2.4.5 might allow local users to overwrite arbitrary files via a symlink attack on a tmp$RANDOM.tmp temporary file. NOTE: there may not be common usage scenari…
- CVE-2008-3927HIGHCVSS v2 7.2EG 7.22008-09-04
genmsgidx in Tiger 3.2.2 allows local users to overwrite or delete arbitrary files via a symlink attack on temporary files.
- CVE-2008-3929HIGHCVSS v2 7.2EG 7.22008-09-04
gather-messages.sh in Ampache 3.4.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/filelist temporary file.
- CVE-2008-3883HIGHCVSS v2 7.2EG 7.22008-09-02
configvar in Caudium 1.4.12 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/roken#####.pike temporary file.
- CVE-2008-1901HIGHCVSS v2 7.2EG 7.22008-04-22
aptlinex before 0.91 allows local users to overwrite arbitrary files via a symlink attack on the gambas-apt.lock temporary file.
- CVE-2008-0930HIGHCVSS v2 7.2EG 7.22008-03-04
w_editeur.c in XWine 1.0.1 for Debian GNU/Linux allows local users to overwrite or print arbitrary files via a symlink attack on the temporaire temporary file. NOTE: some of these details are obtained from third party information.
- CVE-2008-1078HIGHCVSS v2 7.2EG 7.22008-02-29
expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files via a symlink attack on the expn[PID] temporary file. NOTE: this is the same issue as CVE-2003-0308…
- CVE-2004-0967HIGHCVSS v2 7.2EG 7.22005-02-09
The (1) pj-gs.sh, (2) ps2epsi, (3) pv.sh, and (4) sysvlp.sh scripts in the ESP Ghostscript (espgs) package in Trustix Secure Linux 1.5 through 2.1, and other operating systems, allow local users to overwrite files via a symlink attack on t…
- CVE-2003-1528HIGHCVSS v2 7.2EG 7.22003-12-31
nsr_shutdown in Fujitsu Siemens NetWorker 6.0 allows local users to overwrite arbitrary files via a symlink attack on the nsrsh[PID] temporary file.
- CVE-2002-2382HIGHCVSS v2 7.2EG 7.22002-12-31
cvsupd.sh in CVSup 1.2 allows local users to overwrite arbitrary files and gain privileges via a symlink attack on /var/tmp/cvsupd.out.
- CVE-2026-88016HIGHCVSS 7.1EG 7.12026-09-10
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, when backend/local runs with --links, a source .rclonelink object can plant a symlink in the destination and lat…
- CVE-2026-81727HIGHCVSS 7.1EG 7.12026-08-27
NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardli…
- CVE-2026-49114HIGHCVSS 7.1EG 7.12026-08-21
In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_data location field and opens it for writing without 'O_NOFOLLOW/O_EXCL', after a non-atomic 'os.path.isfile()' check. A …
- CVE-2026-17106HIGHCVSS 7.1EG 7.12026-08-18
The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extractor decides where each archive entry lan…
- CVE-2026-63426HIGHCVSS 7.1EG 7.12026-08-13
During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges.
- CVE-2026-12036HIGHCVSS 7.1EG 7.12026-08-13
An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to perform an arbitrary file deletion with elevated privileges.
- CVE-2026-53785HIGHCVSS 7.1EG 7.12026-08-13
rsync before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to write files outside the intended destination directory tree by crafting relative paths with symlink components in --relative mode. The make_path…
- CVE-2026-53784HIGHCVSS 7.1EG 7.12026-08-13
rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intended module root when use chroot is disabled and the module root path or a component of it is a symlink. The daemon call…
- CVE-2026-72694HIGHCVSS 7.1EG 7.12026-08-11
A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can exploit a symbolic link (symlink) following vulnerability. By influencing or pre-placing a sym…
- CVE-2026-71556HIGHCVSS 7.1EG 7.12026-08-07
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution…
- CVE-2026-62189HIGHCVSS 7.1EG 7.12026-07-13
OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower-trust callers to perform actions requiring stronger authorization. Attackers can exploit remote symlink parents to byp…
- CVE-2026-50163HIGHCVSS 7.1EG 7.12026-07-01
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/utils.go:262-275 validates a hardlink target relative to the extract base but returns the unresolved target, causing os.Link("victim.secret"…
- CVE-2026-54371HIGHCVSS 7.1EG 7.12026-06-29
attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarch…
- CVE-2026-54369HIGHCVSS 7.1EG 7.12026-06-29
acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by…
- CVE-2026-54056HIGHCVSS 7.1EG 7.12026-06-12
Kitty is a cross-platform GPU based terminal. In versions 0.47.0 and 0.47.1, `kitten dnd` can allow a malicious remote drag-and-drop source to overwrite or truncate arbitrary files writable by the local kitty user. Remote `text/uri-list` d…
- CVE-2026-49135HIGHCVSS 7.1EG 7.12026-06-01
CodexBar prior to 0.32.0 contains an insecure temporary file handling vulnerability that allows local attackers to access sensitive credentials or tamper with build artifacts by exploiting predictable file paths in the release notarization…
- CVE-2026-0827HIGHCVSS 7.1EG 7.12026-04-15
During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage that, during installation or when using hardware scan, could allow a local authenticate…
- CVE-2026-34604HIGHCVSS 7.1EG 7.12026-04-01
Tina is a headless content management system. Prior to version 2.2.2, @tinacms/graphql uses string-based path containment checks in FilesystemBridge. That blocks plain ../ traversal, but it does not resolve symlink or junction targets. If …
- CVE-2026-34603HIGHCVSS 7.1EG 7.12026-04-01
Tina is a headless content management system. Prior to version 2.2.2, @tinacms/cli recently added lexical path-traversal checks to the dev media routes, but the implementation still validates only the path string and does not resolve symli…
- CVE-2025-66680HIGHCVSS 7.1EG 7.12026-03-03
An issue in the WiseDelfile64.sys component of WiseCleaner Wise Force Deleter 7.3.2 and earlier allows attackers to delete arbitrary files via a crafted request.
- CVE-2026-27967HIGHCVSS 7.1EG 7.12026-02-26
Zed, a code editor, has a symlink escape vulnerability in versions prior to 0.225.9 in Agent file tools (`read_file`, `edit_file`). It allows reading and writing files **outside the project directory** when a project contains symbolic link…
- CVE-2025-62676HIGHCVSS 7.1EG 7.12026-02-10
An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.4, FortiClientWindows 7.2.0 through 7.2.12, FortiClientWindows 7.0 all versions may all…
- CVE-2025-15313HIGHCVSS 7.1EG 7.12026-02-10
Tanium addressed an arbitrary file deletion vulnerability in Tanium EUSS.
- CVE-2026-23563HIGHCVSS 7.1EG 7.12026-01-29
Improper Link Resolution Before File Access (invoked by 1E‑Explorer‑TachyonCore‑DeleteFileByPath instruction) in TeamViewer DEX - 1E Client before version 26.1 on Windows allows a low‑privileged local attacker to delete protected s…
- CVE-2026-24046HIGHCVSS 7.1EG 7.12026-01-21
Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder t…
- CVE-2025-3771HIGHCVSS 7.1EG 7.12025-06-26
A path or symbolic link manipulation vulnerability in SIR 1.0.3 and prior versions allows an authenticated non-admin local user to overwrite system files with SIR backup files, which can potentially cause a system crash. This was achieved …
- CVE-2024-12216HIGHCVSS 7.1EG 7.12025-03-20
A vulnerability in the `ImageClassificationDataset.from_csv()` API of the `dmlc/gluon-cv` repository, version 0.10.0, allows for arbitrary file write. The function downloads and extracts `tar.gz` files from URLs without proper sanitization…
- CVE-2025-25008HIGHCVSS 7.1EG 7.12025-03-11
Improper link resolution before file access ('link following') in Microsoft Windows allows an authorized attacker to elevate privileges locally.
- CVE-2025-21419HIGHCVSS 7.1EG 7.12025-02-11
Windows Setup Files Cleanup Elevation of Privilege Vulnerability
- CVE-2024-52535HIGHCVSS 7.1EG 7.12024-12-25
Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symbolic link (symlink) attack vulnerability in the software remediation component. A low-privileged authe…
- CVE-2024-44258HIGHCVSS 7.1EG 7.12024-10-28
This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, tvOS 18.1, visionOS 2.1. Restoring a maliciously crafted backup file may lead to modification of pr…
- CVE-2024-38097HIGHCVSS 7.1EG 7.12024-10-08
Azure Monitor Agent Elevation of Privilege Vulnerability
- CVE-2024-38188HIGHCVSS 7.1EG 7.12024-09-10
Azure Network Watcher VM Agent Elevation of Privilege Vulnerability
- CVE-2024-35254HIGHCVSS 7.1EG 7.12024-06-11
Azure Monitor Agent Elevation of Privilege Vulnerability
- CVE-2024-23459HIGHCVSS 7.1EG 7.12024-05-02
An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Mac allows a system file to be overwritten.This issue affects Zscaler Client Connector on Mac : before 3.7.
- CVE-2023-36399HIGHCVSS 7.1EG 7.12023-11-14
Windows Storage Elevation of Privilege Vulnerability
Map vulnerabilities like CWE-59 to your infrastructure
EchelonGraph correlates every CVE — across CWE-59 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →