CWE-59— Improper Link Resolution Before File Access (Link Following)
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.— MITRE CWE catalog
1,750 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-59page 21 of 35
- CVE-2008-4942MEDIUMCVSS v2 6.9EG 6.92008-11-05
audiolink in audiolink 0.05 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/audiolink.db.tmp and (2) /tmp/audiolink.tb.tmp temporary files.
- CVE-2008-4941MEDIUMCVSS v2 6.9EG 6.92008-11-05
arb-common 0.0.20071207.1 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/arb_fdnaml_*, (b) /tmp/arb_pids_*, (c) /tmp/arbdsmz.html, and (d) /tmp/arbdsmz.htm temporary files, related to the (1) arb_fastdnaml…
- CVE-2008-4940MEDIUMCVSS v2 6.9EG 6.92008-11-05
xmlfile.py in aptoncd 0.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/aptoncd temporary file.
- CVE-2008-4939MEDIUMCVSS v2 6.9EG 6.92008-11-05
apertium 3.0.7 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/#####.lex.cc, (b) /tmp/#####.deformat.l, (c) /tmp/#####.reformat.l, (d) /tmp/#####docxorig, (e) /tmp/#####docxsalida.zip, (f) /tmp/#####xlsxemb…
- CVE-2008-4938MEDIUMCVSS v2 6.9EG 6.92008-11-05
aegis 4.24 and aegis-web 4.24 allow local users to overwrite arbitrary files via a symlink attack on (a) /tmp/#####, (b) /tmp/#####.intro, (c) /tmp/aegis.#####.ae, (d) /tmp/aegis.#####, (e) /tmp/aegis.#####.1, (f) /tmp/aegis.#####.2, (g) /…
- CVE-2008-4936MEDIUMCVSS v2 6.9EG 6.92008-11-05
faxspool in mgetty 1.1.36 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/faxsp.##### temporary file.
- CVE-2008-4935MEDIUMCVSS v2 6.9EG 6.92008-11-05
asciiview in aview 1.3.0 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/aview#####.pgm temporary file.
- CVE-2008-4476MEDIUMCVSS v2 6.9EG 6.92008-10-07
sympa.pl in sympa 5.3.4 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/sympa_aliases.$$ temporary file. NOTE: wwsympa.fcgi was also reported, but the issue occurred in a dead function, so it is not a vuln…
- CVE-2008-4192MEDIUMCVSS v2 6.9EG 6.92008-09-29
The pserver_shutdown function in fence_egenera in cman 2.20080629 and 2.20080801 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/eglog temporary file.
- CVE-2008-3928MEDIUMCVSS v2 6.9EG 6.92008-09-04
test.sh in Honeyd 1.5c might allow local users to overwrite arbitrary files via a symlink attack on a temporary file.
- CVE-2008-3930MEDIUMCVSS v2 6.9EG 6.92008-09-04
migrate_aliases.sh in Citadel Server 7.37 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
- CVE-2008-3931MEDIUMCVSS v2 6.9EG 6.92008-09-04
javareconf in R 2.7.2 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
- CVE-2008-1103MEDIUMCVSS v2 6.9EG 6.92008-04-28
Multiple unspecified vulnerabilities in Blender have unknown impact and attack vectors, related to "temporary file issues."
- CVE-2007-5664MEDIUMCVSS v2 6.9EG 6.92008-04-16
db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16 allows local users to overwrite arbitrary files via a symlink attack on files used for ini…
- CVE-2008-1417MEDIUMCVSS v2 6.9EG 6.92008-03-20
The prerm script in axyl 2.1.7 allows local users to overwrite arbitrary files via a symlink attack on the axyl.conf temporary file.
- CVE-2007-4998MEDIUMCVSS v2 6.9EG 6.92008-01-31
cp, when running with an option to preserve symlinks on multiple OSes, allows local, user-assisted attackers to overwrite arbitrary files via a symlink attack using crafted directories containing multiple source files that are copied to th…
- CVE-2007-5805MEDIUMCVSS v2 6.9EG 6.92007-11-05
cfgcon in IBM AIX 5.2 and 5.3 does not properly validate the argument to the "-p" option to swcons, which allows local users in the system group to create an arbitrary file, and enable world writability of this file, via a symlink attack i…
- CVE-2007-5377MEDIUMCVSS v2 6.9EG 6.92007-10-12
The (1) tramp-make-temp-file and (2) tramp-make-tramp-temp-file functions in Tramp 2.1.10 extension for Emacs, and possibly earlier 2.1.x versions, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
- CVE-2007-4631MEDIUMCVSS v2 6.9EG 6.92007-08-31
The DataLoader::doStart function in dataloader.cpp in QGit 1.5.6 and other versions up to 2pre1 allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack on temporary files with predictable filenames.
- CVE-2002-0824MEDIUMCVSS v2 6.9EG 6.92002-08-12
BSD pppd allows local users to change the permissions of arbitrary files via a symlink attack on a file that is specified as a tty device.
- CVE-2026-108759MEDIUMCVSS 6.8EG 6.82026-10-11
mistral.rs 0.9.0 through 0.9.4 contains a link following vulnerability in mistralrs-code-exec that allows sandboxed shell code to read and overwrite files outside the sandbox via symlinks. Attackers or prompt-injected agents can name symli…
- CVE-2026-90930MEDIUMCVSS 6.8EG 6.82026-09-14
File Browser through 2.63.23 applies path rules to the requested lexical path but resolves symbolic links without reapplying rules to the target, allowing authenticated users to bypass deny rules. Attackers can read and overwrite rule-deni…
- CVE-2026-59311MEDIUMCVSS 6.8EG 6.82026-08-27
A local unprivileged user on the same host can redirect all Zip/UnZip transformer output into a directory of their choosing by pre-creating /tmp/ziptransformer as a symlink before the application starts. Spring Integration 7.1.0 Spring Int…
- CVE-2026-18267MEDIUMCVSS 6.8EG 6.82026-08-20
Kenwood DNR1007XR Firmware Update Link Following Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DNR1007XR devices. Authentication is not r…
- CVE-2026-41397MEDIUMCVSS 6.8EG 6.82026-04-28
OpenClaw before 2026.3.31 contains a sandbox escape vulnerability allowing attackers to traverse directory boundaries through symlink exploitation during file synchronization operations. Remote attackers can bypass sandbox restrictions by …
- CVE-2026-2808MEDIUMCVSS 6.8EG 6.82026-03-11
HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.
- CVE-2025-67124MEDIUMCVSS 6.8EG 6.82026-01-23
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can creat…
- CVE-2026-23893MEDIUMCVSS 6.8EG 6.82026-01-22
openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. Versions 2.3.2 and above are vulnerable to symlink-following when running in privileged contexts. A token-group user can redirect file operations to arbitrary filesy…
- CVE-2025-5718MEDIUMCVSS 6.8EG 6.82025-11-11
The ACAP Application framework could allow privilege escalation through a symlink attack. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacke…
- CVE-2024-30076MEDIUMCVSS 6.8EG 6.82024-06-11
Windows Container Manager Service Elevation of Privilege Vulnerability
- CVE-2023-28972MEDIUMCVSS 6.8EG 6.82023-04-17
An Improper Link Resolution Before File Access vulnerability in console port access of Juniper Networks Junos OS on NFX Series allows an attacker to bypass console access controls. When "set system ports console insecure" is enabled, root …
- CVE-2023-27850MEDIUMCVSS 6.8EG 6.82023-03-10
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a file sharing mechanism that allows users with access to this feature to access arbitrary files on the device.
- CVE-2021-20153MEDIUMCVSS 6.8EG 6.82021-12-30
Trendnet AC2600 TEW-827DRU version 2.08B01 contains a symlink vulnerability in the bittorrent functionality. If enabled, the bittorrent functionality is vulnerable to a symlink attack that could lead to remote code execution on the device.…
- CVE-2019-3690MEDIUMCVSS 6.8EG 6.82019-12-05
The chkstat tool in the permissions package followed symlinks before commit a9e1d26cd49ef9ee0c2060c859321128a6dd4230 (please also check the additional hardenings after this fix). This allowed local attackers with control over a path that i…
- CVE-2019-12672MEDIUMCVSS 6.8EG 6.82019-09-25
A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker with physical access to an affected device to execute arbitrary code on the underlying operating system (OS) with root privileges. The …
- CVE-2013-0248MEDIUMCVSS 6.8EG 6.82013-03-15
The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.
- CVE-2011-0402MEDIUMCVSS v2 6.8EG 6.82011-01-11
dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via a symlink attack on unspecified files in the .pc directory.
- CVE-2009-0473MEDIUMCVSS v2 6.8EG 6.82009-02-06
Open redirect vulnerability in the web interface in the Rockwell Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge Module allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified ve…
- CVE-2007-2978MEDIUMCVSS v2 6.8EG 6.82007-06-01
Session fixation vulnerability in eggblog 3.1.0 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
- CVE-2005-2714MEDIUMCVSS v2 6.8EG 6.82005-12-31
passwd in Directory Services in Mac OS X 10.3.x before 10.3.9 and 10.4.x before 10.4.5 allows local users to overwrite arbitrary files via a symlink attack on the .pwtmp.[PID] temporary file.
- CVE-2026-107578MEDIUMCVSS 6.7EG 6.72026-10-08
Improper link resolution and external control of file paths in the administrative command-line operations of hMailServer.exe in Progressive Robot hMailServer 6.3.4 and 6.3.5 allow a local attacker who already runs code as the low-privilege…
- CVE-2026-65680MEDIUMCVSS 6.7EG 6.72026-08-11
Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.
- CVE-2026-40977MEDIUMCVSS 6.7EG 6.72026-04-28
When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location can corrupt one file on the host each time the application is started. Affected: Spring Boot 4.0.0–4.0.5 …
- CVE-2026-35349MEDIUMCVSS 6.7EG 6.72026-04-22
A vulnerability in the rm utility of uutils coreutils allows a bypass of the --preserve-root protection. The implementation uses a path-string check rather than comparing device and inode numbers to identify the root directory. An attacker…
- CVE-2025-24918MEDIUMCVSS 6.7EG 6.72025-11-11
Improper link resolution before file access ('link following') for some Intel(R) Server Configuration Utility software and Intel(R) Server Firmware Update Utility software before version 16.0.12. within Ring 3: User Applications may allow …
- CVE-2025-43726MEDIUMCVSS 6.7EG 6.72025-09-02
Dell Alienware Command Center 5.x (AWCC), versions prior to 5.10.2.0, contains an Improper Link Resolution Before File Access ('Link Following')" vulnerability. A low privileged attacker with local access could potentially exploit this vul…
- CVE-2025-29983MEDIUMCVSS 6.7EG 6.72025-04-15
Dell Trusted Device, versions prior to 7.0.3.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to E…
- CVE-2023-43078MEDIUMCVSS 6.7EG 6.72024-08-28
Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege Escalation or Denial of Service.
- CVE-2024-38013MEDIUMCVSS 6.7EG 6.72024-07-09
Microsoft Windows Server Backup Elevation of Privilege Vulnerability
- CVE-2024-5742MEDIUMCVSS 6.7EG 6.72024-06-12
A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a…
Map vulnerabilities like CWE-59 to your infrastructure
EchelonGraph correlates every CVE — across CWE-59 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →