CWE-59— Improper Link Resolution Before File Access (Link Following)
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.— MITRE CWE catalog
1,746 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-59page 2 of 35
- CVE-2022-34960CRITICALCVSS 9.8EG 9.82022-08-25
The container package in MikroTik RouterOS 7.4beta4 allows an attacker to create mount points pointing to symbolic links, which resolve to locations on the host device. This allows the attacker to mount any arbitrary file to any location o…
- CVE-2022-26612CRITICALCVSS 9.8EG 9.82022-04-07
In Apache Hadoop, The unTar function uses unTarUsingJava function on Windows and the built-in tar utility on Unix and other OSes. As a result, a TAR entry may create a symlink under the expected extraction directory which points to an exte…
- CVE-2021-21691CRITICALCVSS 9.8EG 9.82021-11-04
Creating symbolic links is possible without the 'symlink' agent-to-controller access control permission in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.
- CVE-2020-27172CRITICALCVSS 9.8EG 9.82020-12-28
An issue was discovered in G-Data before 25.5.9.25 using Symbolic links, it is possible to abuse the infected-file restore mechanism to achieve arbitrary write that leads to elevation of privileges.
- CVE-2020-9682CRITICALCVSS 9.8EG 9.82020-07-17
Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability. Successful exploitation could lead to arbitrary file system write.
- CVE-2020-9670CRITICALCVSS 9.8EG 9.82020-07-17
Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability. Successful exploitation could lead to privilege escalation.
- CVE-2020-12265CRITICALCVSS 9.8EG 9.82020-04-26
The decompress package before 4.2.1 for Node.js is vulnerable to Arbitrary File Write via ../ in an archive member, when a symlink is used, because of Directory Traversal.
- CVE-2019-7183CRITICALCVSS 9.8EG 9.82019-12-05
This improper link resolution vulnerability allows remote attackers to access system files. To fix this vulnerability, QNAP recommend updating QTS to their latest versions.
- CVE-2019-18658CRITICALCVSS 9.8EG 9.82019-11-12
In Helm 2.x before 2.15.2, commands that deal with loading a chart as a directory or packaging a chart provide an opportunity for a maliciously designed chart to include sensitive content such as /etc/passwd, or to execute a denial of serv…
- CVE-2018-1000544CRITICALCVSS 9.8EG 9.82018-06-26
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploadi…
- CVE-2018-12026CRITICALCVSS 9.8EG 9.82018-06-17
During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows such applications to replace key files or directories in the spawning communication directory with symlinks. This …
- CVE-2003-1233CRITICALCVSS 9.8EG 9.82003-12-31
Pedestal Software Integrity Protection Driver (IPD) 1.3 and earlier allows privileged attackers, such as rootkits, to bypass file access restrictions to the Windows kernel by using the NtCreateSymbolicLinkObject function to create a symbol…
- CVE-2025-69431CRITICALCVSS 6.1EG 9.82026-02-03
The ZSPACE Q2C NAS contains a vulnerability related to incorrect symbolic link following. Attackers can format a USB drive to ext4, create a symbolic link to its root directory, insert the drive into the NAS device's slot, and then access …
- CVE-2025-69430CRITICALCVSS 6.1EG 9.82026-02-03
An Incorrect Symlink Follow vulnerability exists in multiple Yottamaster NAS devices, including DM2 (version equal to or prior to V1.9.12), DM3 (version equal to or prior to V1.9.12), and DM200 (version equal to or prior to V1.2.23) that c…
- CVE-2025-24278CRITICALCVSS 5.5EG 9.82025-03-31
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access protected user data.
- CVE-2025-24242CRITICALCVSS 4.4EG 9.82025-03-31
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app with root privileges may be able to access private information.
- CVE-2026-100715CRITICALCVSS 9.6EG 9.62026-09-26
Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task. Cron task 8 (deleteFtpData), queued when an FTP account is deleted, calls FileDir::makeCorrectDir() without the $fixe…
- CVE-2026-57571CRITICALCVSS 9.6EG 9.62026-07-06
Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded file, the destination filename was taken from attacker-influenced input and joined to the downloads directory with no conf…
- CVE-2026-54352CRITICALCVSS 9.6EG 9.62026-06-22
Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packages/server/src/api/routes/static.ts:24 accepts a builder-uploaded .zip, extracts it with [email protected] into a temp directory, then for e…
- CVE-2026-53476CRITICALCVSS 9.6EG 9.62026-06-10
A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal vulnerability. By crafting a specially designed gzipped tarball, the attacker can bypass …
- CVE-2023-25168CRITICALCVSS 9.6EG 9.62023-02-09
Wings is Pterodactyl's server control plane. This vulnerability can be used to delete files and directories recursively on the host system. This vulnerability can be combined with `GHSA-p8r3-83r8-jwj5` to overwrite files on the host syste…
- CVE-2017-1002101CRITICALCVSS 8.8EG 9.62018-03-13
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/direc…
- CVE-2026-94620CRITICALCVSS 9.4EG 9.42026-10-01
Classroom 50 is a free and open-source tool for managing and grading programming assignments via GitHub. Prior to version 1.11.0, `gh teacher download` clones each student's assignment repository and then writes autograde artifacts (`resul…
- CVE-2026-68491CRITICALCVSS 9.4EG 9.42026-09-15
An insufficient check allowed for the overwrite of arbitrary files via a symlink.
- CVE-2026-77179CRITICALCVSS 9.4EG 9.42026-09-15
On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and …
- CVE-2026-47187CRITICALCVSS 9.3EG 9.32026-08-19
SSHFS is a network filesystem client for connecting to SSH servers. Prior to version 3.7.6, a rogue SFTP server can return absolute symlink targets or relative targets containing parent-directory components that SSHFS passes through FUSE f…
- CVE-2025-52936CRITICALCVSS 9.3EG 9.32025-06-23
Improper Link Resolution Before File Access ('Link Following') vulnerability in yrutschle sslh.This issue affects sslh: before 2.2.2.
- CVE-2008-5155HIGHCVSS v2 9.3EG 9.32008-11-18
mail2sms.sh in smsclient 2.0.8z allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/header.##### or (2) /tmp/body.##### temporary file, or append data to arbitrary files via a symlink attack on the (3) /tmp/s…
- CVE-2008-4694HIGHCVSS v2 9.3EG 9.32008-10-23
Unspecified vulnerability in Opera before 9.60 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a redirect that specifies a crafted URL.
- CVE-2008-3329HIGHCVSS v2 9.3EG 9.32008-07-27
Unspecified vulnerability in Links before 2.1, when "only proxies" is enabled, has unknown impact and attack vectors related to providing "URLs to external programs."
- CVE-2026-12503CRITICALCVSS 9.2EG 9.22026-07-24
Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an authenticated `larmapp` attacker to make `/etc/passwd` writable by the `larma…
- CVE-2026-101894CRITICALCVSS 9.1EG 9.12026-09-28
The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel following a planted symlink chain. An attac…
- CVE-2026-20310CRITICALCVSS 9.1EG 9.12026-08-05
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that ad…
- CVE-2026-53486CRITICALCVSS 9.1EG 9.12026-07-06
The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting an archive to a directory, a crafted archive can read or write fi…
- CVE-2026-25718CRITICALCVSS 9.1EG 9.12026-07-03
Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processing to read or write through symlinked or otherwise non-regular paths.
- CVE-2026-42496CRITICALCVSS 9.1EG 9.12026-05-26
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths…
- CVE-2024-10007CRITICALCVSS 9.1EG 9.12024-11-07
A path collision and arbitrary code execution vulnerability was identified in GitHub Enterprise Server that allowed container escape to escalate to root via ghe-firejail path. Exploitation of this vulnerability requires Enterprise Administ…
- CVE-2024-3829CRITICALCVSS 9.1EG 9.12024-06-03
qdrant/qdrant version 1.9.0-dev is vulnerable to arbitrary file read and write during the snapshot recovery process. Attackers can exploit this vulnerability by manipulating snapshot files to include symlinks, leading to arbitrary file rea…
- CVE-2023-39107CRITICALCVSS 9.1EG 9.12023-08-04
An arbitrary file overwrite vulnerability in NoMachine Free Edition and Enterprise Client for macOS before v8.8.1 allows attackers to overwrite root-owned files by using hardlinks.
- CVE-2022-23144CRITICALCVSS 9.1EG 9.12022-09-23
There is a broken access control vulnerability in ZTE ZXvSTB product. Due to improper permission control, attackers could use this vulnerability to delete the default application type, which affects normal use of system.
- CVE-2021-38570CRITICALCVSS 9.1EG 9.12021-08-11
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows attackers to delete arbitrary files (during uninstallation) via a symlink.
- CVE-2020-13833CRITICALCVSS 9.1EG 9.12020-06-04
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The system area allows arbitrary file overwrites via a symlink attack. The Samsung ID is SVE-2020-17183 (June 2020).
- CVE-2021-32825CRITICALCVSS 2.7EG 9.12021-08-16
bblfshd is an open source self-hosted server for source code parsing. In bblfshd before commit 4265465b9b6fb5663c30ee43806126012066aad4 there is a "zipslip" vulnerability. The unsafe handling of symbolic links in an unpacking routine may e…
- CVE-2026-52811CRITICALCVSS 9.0EG 9.02026-06-23
Gogs is an open source self-hosted Git service. Prior to 0.14.3, (*Repository).UploadRepoFiles checks for symlinks only on the leaf of the upload target (osx.IsSymlink(targetPath)). The siblings UpdateRepoFile, DeleteRepoFile, and GetDiffP…
- CVE-2024-32002CRITICALCVSS 9.0EG 9.02024-05-14
Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a way that exploits a bug in Git whereby it can be fooled into writing files not…
- CVE-2021-21300CRITICALCVSS 8.0EG 9.02021-03-09
Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as well as files using a clean/smudge filter such as Git LFS, may cause just-checked out scr…
- CVE-2026-89091HIGHCVSS 8.8EG 8.82026-10-08
A flaw was found in ansible-core. When installing a collection with `ansible-galaxy collection install`, the archive extractor validates member paths using lexical path normalisation (os.path.abspath) instead of resolving symbolic links (o…
- CVE-2026-15815HIGHCVSS 8.8EG 8.82026-09-17
Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin installation directory, writing arbitrary file…
- CVE-2026-85731HIGHCVSS 8.8EG 8.82026-09-16
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, content/file.Store extraction of OCI layers marked with io.deis.oras.content.unpack=true can write outside the store working directory. The pushDir path through extractTar…
- CVE-2026-87766HIGHCVSS 8.8EG 8.82026-09-09
A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching user. This ha…
Map vulnerabilities like CWE-59 to your infrastructure
EchelonGraph correlates every CVE — across CWE-59 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →