CWE-59— Improper Link Resolution Before File Access (Link Following)
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.— MITRE CWE catalog
1,750 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-59page 22 of 35
- CVE-2024-31952MEDIUMCVSS 6.7EG 6.72024-05-14
An issue was discovered in Samsung Magician 8.0.0 on macOS. Because symlinks are used during the installation process, an attacker can escalate privileges via arbitrary file permission writes. (The attacker must already have user privilege…
- CVE-2023-28065MEDIUMCVSS 6.7EG 6.72023-06-23
Dell Command | Update, Dell Update, and Alienware Update versions 4.8.0 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability leading t…
- CVE-2023-28141MEDIUMCVSS 6.7EG 6.72023-04-18
An NTFS Junction condition exists in the Qualys Cloud Agent for Windows platform in versions before 4.8.0.31. Attackers may write files to arbitrary locations via a local attack vector. This allows attackers to assume the privileges of th…
- CVE-2009-1142MEDIUMCVSS 6.7EG 6.72022-11-23
An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can gain privileges via a symlink attack on /tmp files if vmware-user-suid-wrapper is setuid root and the ChmodChownDirectory function is enabled.
- CVE-2022-21770MEDIUMCVSS 6.7EG 6.72022-07-06
In sound driver, there is a possible information disclosure due to symlink following. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0…
- CVE-2021-42056MEDIUMCVSS 6.7EG 6.72022-06-24
Thales Safenet Authentication Client (SAC) for Linux and Windows through 10.7.7 creates insecure temporary hid and lock files allowing a local attacker, through a symlink attack, to overwrite arbitrary files, and potentially achieve arbitr…
- CVE-2022-20085MEDIUMCVSS 6.7EG 6.72022-05-03
In netdiag, there is a possible symbolic link following due to an improper link resolution. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID…
- CVE-2022-20068MEDIUMCVSS 6.7EG 6.72022-04-11
In mobile_log_d, there is a possible symbolic link following due to an improper link resolution. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Pat…
- CVE-2022-20050MEDIUMCVSS 6.7EG 6.72022-03-10
In connsyslogger, there is a possible symbolic link following due to improper link resolution. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch…
- CVE-2020-10665MEDIUMCVSS 6.7EG 6.72020-03-18
Docker Desktop allows local privilege escalation to NT AUTHORITY\SYSTEM because it mishandles the collection of diagnostics with Administrator privileges, leading to arbitrary DACL permissions overwrites and arbitrary file writes. This aff…
- CVE-2018-1634MEDIUMCVSS 6.7EG 6.72019-08-20
IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in infos.DBSERVERNAME. IBM X-Force ID: 144437.
- CVE-2018-1633MEDIUMCVSS 6.7EG 6.72019-08-20
IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in onsrvapd. IBM X-Force ID: 144434.
- CVE-2018-1632MEDIUMCVSS 6.7EG 6.72019-08-20
IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in .infxdirs. IBM X-Force ID: 144432.
- CVE-2018-1631MEDIUMCVSS 6.7EG 6.72019-08-20
IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in oninit mongohash. IBM X-Force ID: 144431.
- CVE-2018-1630MEDIUMCVSS 6.7EG 6.72019-08-20
IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in onmode. IBM X-Force ID: 144430.
- CVE-2017-12172MEDIUMCVSS 6.7EG 6.72017-11-22
PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, 9.3.x before 9.3.20, and 9.2.x before 9.2.24 runs under a non-root operating system account, and database superusers have effective ability to run a…
- CVE-2017-9525MEDIUMCVSS 6.7EG 6.72017-06-09
In the cron package through 3.0pl1-128 on Debian, and through 3.0pl1-128ubuntu2 on Ubuntu, the postinst maintainer script allows for group-crontab-to-root privilege escalation via symlink attacks against unsafe usage of the chown and chmod…
- CVE-2017-15097MEDIUMCVSS 6.5EG 6.72018-07-27
Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user account could use these flaws to obtain root access on the server machine.
- CVE-2026-81310MEDIUMCVSS 6.6EG 6.62026-09-30
Image Scanner Driver for Linux contains a link following vulnerability. An attacker who can log in to a Linux system where the product is installed may overwrite arbitrary files by using a special method in advance.
- CVE-2026-85092MEDIUMCVSS 6.6EG 6.62026-09-03
LiME through 1.12.0 fails to validate the disk acquisition output path and does not use O_NOFOLLOW when opening the operator-supplied path parameter, allowing unprivileged local users to overwrite arbitrary root-owned files. An attacker wh…
- CVE-2026-55569MEDIUMCVSS 6.6EG 6.62026-08-28
aqua is a declarative command-line version manager written in Go. Prior to 2.60.1, pkg/unarchive/archives.go in the handler.HandleFile method calls os.Symlink with archives.FileInfo.LinkTarget without verifying that the target remains unde…
- CVE-2026-56796MEDIUMCVSS 6.6EG 6.62026-08-19
Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading …
- CVE-2026-62239MEDIUMCVSS 6.6EG 6.62026-07-13
FlashAttention through 2.8.3.post1, fixed in commit 0816ef1, contains a symlink attack vulnerability in the download_and_copy() function within hopper/setup.py that extracts NVIDIA toolchain archives without validating symlinks or filterin…
- CVE-2026-6941MEDIUMCVSS 6.6EG 6.62026-04-23
radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to read or write files outside the configured project directory by importing a malicious .zrp archive containing a symlinked…
- CVE-2026-35365MEDIUMCVSS 6.6EG 6.62026-04-22
The mv utility in uutils coreutils improperly handles directory trees containing symbolic links during moves across filesystem boundaries. Instead of preserving symlinks, the implementation expands them, copying the linked targets as real …
- CVE-2026-28684MEDIUMCVSS 6.6EG 6.62026-04-20
python-dotenv reads key-value pairs from a .env file and can set them as environment variables. Prior to version 1.2.2, `set_key()` and `unset_key()` in python-dotenv follow symbolic links when rewriting `.env` files, allowing a local atta…
- CVE-2026-4135MEDIUMCVSS 6.6EG 6.62026-04-15
During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to perform an arbitrary file write with elevated privileges.
- CVE-2026-21419MEDIUMCVSS 6.6EG 6.62026-02-09
Dell Display and Peripheral Manager (Windows) versions prior to 2.2 contain an Improper Link Resolution Before File Access ('Link Following') vulnerability in the Installer and Service. A low privileged attacker with local access could pot…
- CVE-2025-15324MEDIUMCVSS 6.6EG 6.62026-02-05
Tanium addressed a documentation issue in Engage.
- CVE-2025-46636MEDIUMCVSS 6.6EG 6.62025-12-09
Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Infor…
- CVE-2023-32474MEDIUMCVSS 6.6EG 6.62024-02-06
Dell Display Manager application, version 2.1.1.17 and prior, contain an insecure operation on windows junction/mount point. A local malicious user could potentially exploit this vulnerability during installation leading to arbitrary fold…
- CVE-2025-14693MEDIUMCVSS 6.2EG 6.62025-12-15
A vulnerability has been found in Ugreen DH2100+ up to 5.3.0. This affects an unknown function of the component USB Handler. Such manipulation leads to symlink following. The attack can be executed directly on the physical device. The expl…
- CVE-2008-4191MEDIUMCVSS v2 6.6EG 6.62008-09-24
extract-table.pl in Emacspeak 26 and 28 allows local users to overwrite arbitrary files via a symlink attack on the extract-table.csv temporary file.
- CVE-2026-106508MEDIUMCVSS 6.5EG 6.52026-10-06
Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by potential file exposure through local techdocs publisher. When using the local TechDocs publisher (t…
- CVE-2026-106507MEDIUMCVSS 6.5EG 6.52026-10-06
Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by techdocs arbitrary file read via mkdocs snippets. Unsafe path resolution in TechDocs source tree han…
- CVE-2026-96279MEDIUMCVSS 6.5EG 6.52026-09-27
A malicious OCI registry can hardlink arbitrary host files into the extraction directory when a user installs or updates a Flatpak application from an OCI remote, allowing disclosure of arbitrary host file contents. For system-wide install…
- CVE-2026-85583MEDIUMCVSS 6.5EG 6.52026-09-04
SiYuan versions before v3.8.2 contain a path traversal vulnerability in the reader-accessible file-read endpoint that follows symlinks when opening authorized asset paths. Attackers with reader role can request a logical asset under data/a…
- CVE-2026-76845MEDIUMCVSS 6.5EG 6.52026-08-24
adm-zip 0.5.9 through 0.6.0 follows symbolic links at the extraction destination. Utils.sanitize in util/utils.js enforces containment by comparing only the string form of an archive entry name against the resolved extraction root, and Uti…
- CVE-2026-55168MEDIUMCVSS 6.5EG 6.52026-08-21
Runtipi is a personal homeserver orchestrator. In 4.10.0 and earlier, Runtipi accepts symbolic links from an attacker-controlled backup archive and copies them into live application paths during the backup restore flow. An authenticated at…
- CVE-2026-71964MEDIUMCVSS 6.5EG 6.52026-08-10
CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file manager component that allows authenticated attackers to read sensitive system files by uploading a crafted ZIP archive containing symboli…
- CVE-2026-70622MEDIUMCVSS 6.5EG 6.52026-08-10
tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function that allows attackers to read files outside the intended source root directory by planting symlinks in an attacker-contr…
- CVE-2026-13723MEDIUMCVSS 6.5EG 6.52026-07-29
A vulnerability in the `zipx.Unzip` extraction routine of Develar's app-builder allows an attacker to overwrite arbitrary files on macOS APFS by exploiting a Unicode Normalization Collision combined with symlink following behavior. APFS tr…
- CVE-2026-14904MEDIUMCVSS 6.5EG 6.52026-07-07
AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create and manage secure virtual desktops and computing resources on AWS. Improper link resolution before file access issue (…
- CVE-2026-58403MEDIUMCVSS 6.5EG 6.52026-07-06
Hugo is a static site generator. From v0.123.0 through v0.163.0, Hugo's virtual filesystem is designed so that files under a mount cannot reach outside the mount tree, but a regression caused RootMappingFs.statRoot to call Stat, which foll…
- CVE-2026-47277MEDIUMCVSS 6.5EG 6.52026-06-17
Runtipi is a personal homeserver orchestrator. In versions 4.9.1 through 4.9.3, Runtipi serves marketplace app logos from files inside cloned app-store repositories through an unauthenticated endpoint, which leads to arbitrary file read th…
- CVE-2026-11853MEDIUMCVSS 6.5EG 6.52026-06-10
Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Debian source packages (.dsc) and upload artifacts (.changes) are manifest files that name the files that make up the artifact. The parser us…
- CVE-2026-11322MEDIUMCVSS 6.5EG 6.52026-06-04
Hermes WebUI prior to v0.51.221 contains a path traversal vulnerability that allows attackers to escape the workspace boundary by supplying symlinks that resolve to files or directories outside the designated workspace root. Attackers can …
- CVE-2026-40861MEDIUMCVSS 6.5EG 6.52026-06-01
A Dag author could either (a) create a symlink under their task's log directory pointing to an arbitrary file readable by the API server process (read-path attack — e.g. `/etc/passwd` or `airflow.cfg`) or (b) supply a `task_id` containin…
- CVE-2026-32054MEDIUMCVSS 6.5EG 6.52026-03-21
OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in browser trace and download output path handling that allows local attackers to escape the managed temp root directory. An attacker with local access can crea…
- CVE-2026-24056MEDIUMCVSS 6.5EG 6.52026-01-26
pnpm is a package manager. Prior to version 10.28.2, when pnpm installs a `file:` (directory) or `git:` dependency, it follows symlinks and reads their target contents without constraining them to the package root. A malicious package cont…
Map vulnerabilities like CWE-59 to your infrastructure
EchelonGraph correlates every CVE — across CWE-59 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →