CWE-59— Improper Link Resolution Before File Access (Link Following)
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.— MITRE CWE catalog
1,750 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-59page 23 of 35
- CVE-2025-57749MEDIUMCVSS 6.5EG 6.52025-08-20
n8n is a workflow automation platform. Before 1.106.0, a symlink traversal vulnerability was discovered in the Read/Write File node in n8n. While the node attempts to restrict access to sensitive directories and files, it does not properly…
- CVE-2025-43252MEDIUMCVSS 6.5EG 6.52025-07-30
This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sequoia 15.6. A website may be able to access sensitive user data when resolving symlinks.
- CVE-2021-1491MEDIUMCVSS 6.5EG 6.52024-11-15
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to read arbitrary files on the underlying file system of the device. This vulnerability is due to in…
- CVE-2023-28869MEDIUMCVSS 6.5EG 6.52023-12-09
Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers read the contents of arbitrary files on the operating system by creating a symbolic link.
- CVE-2023-46655MEDIUMCVSS 6.5EG 6.52023-10-25
Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the directory from which artifacts are published during the 'CloudBees CD - Publish Artifact' post-build step, allowing attackers able to configu…
- CVE-2023-4053MEDIUMCVSS 6.5EG 6.52023-08-01
A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability affects F…
- CVE-2023-4052MEDIUMCVSS 6.5EG 6.52023-08-01
The Firefox updater created a directory writable by non-privileged users. When uninstalling Firefox, any files in that directory would be recursively deleted with the permissions of the uninstalling user account. This could be combined wit…
- CVE-2023-37206MEDIUMCVSS 6.5EG 6.52023-07-05
Uploading files which contain symlinks may have allowed an attacker to trick a user into submitting sensitive data to a malicious website. This vulnerability affects Firefox < 115.
- CVE-2023-34204MEDIUMCVSS 6.5EG 6.52023-05-30
imapsync through 2.229 uses predictable paths under /tmp and /var/tmp in its default mode of operation. Both of these are typically world-writable, and thus (for example) an attacker can modify imapsync's cache and overwrite files belongin…
- CVE-2022-3592MEDIUMCVSS 6.5EG 6.52023-01-12
A symlink following vulnerability was found in Samba, where a user can create a symbolic link that will make 'smbd' escape the configured share path. This flaw allows a remote user with access to the exported part of the file system under …
- CVE-2022-25179MEDIUMCVSS 6.5EG 6.52022-02-15
Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier follows symbolic links to locations outside of the checkout directory for the configured SCM when reading files using the readTrusted step, allowing attackers able to confi…
- CVE-2022-25177MEDIUMCVSS 6.5EG 6.52022-02-15
Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier follows symbolic links to locations outside of the expected Pipeline library when reading files using the libraryResource step, allowing attackers able to confi…
- CVE-2022-25176MEDIUMCVSS 6.5EG 6.52022-02-15
Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier follows symbolic links to locations outside of the checkout directory for the configured SCM when reading the script file (typically Jenkinsfile) for Pipelines, allowing attack…
- CVE-2021-32509MEDIUMCVSS 6.5EG 6.52021-07-07
Absolute Path Traversal vulnerability in FileviewDoc in QSAN Storage Manager allows remote authenticated attackers access arbitrary files by injecting the Symbolic Link following the Url path parameter. The referred vulnerability has been …
- CVE-2021-32508MEDIUMCVSS 6.5EG 6.52021-07-07
Absolute Path Traversal vulnerability in FileStreaming in QSAN Storage Manager allows remote authenticated attackers access arbitrary files by injecting the Symbolic Link following the Url path parameter. The referred vulnerability has bee…
- CVE-2021-21131MEDIUMCVSS 6.5EG 6.52021-02-09
Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.
- CVE-2021-1145MEDIUMCVSS 6.5EG 6.52021-01-13
A vulnerability in the Secure FTP (SFTP) of Cisco StarOS for Cisco ASR 5000 Series Routers could allow an authenticated, remote attacker to read arbitrary files on an affected device. To exploit this vulnerability, the attacker would need …
- CVE-2021-21602MEDIUMCVSS 6.5EG 6.52021-01-13
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows reading arbitrary files using the file browser for workspaces and archived artifacts by following symlinks.
- CVE-2020-27643MEDIUMCVSS 6.5EG 6.52020-12-29
The %PROGRAMDATA%\1E\Client directory in 1E Client 5.0.0.745 and 4.1.0.267 allows remote authenticated users and local users to create and modify files in protected directories (where they would not normally have access to create or modify…
- CVE-2020-3437MEDIUMCVSS 6.5EG 6.52020-07-16
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to read arbitrary files on the underlying filesystem of the device. The vulnerability is due to insufficie…
- CVE-2020-7653MEDIUMCVSS 6.5EG 6.52020-05-29
All versions of snyk-broker before 4.80.0 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users with access to Snyk's internal network by creating symlinks to match whitelisted paths.
- CVE-2020-2024MEDIUMCVSS 6.5EG 6.52020-05-19
An improper link resolution vulnerability affects Kata Containers versions prior to 1.11.0. Upon container teardown, a malicious guest can trick the kata-runtime into unmounting any mount point on the host and all mount points underneath i…
- CVE-2020-8831MEDIUMCVSS 6.5EG 6.52020-04-22
Apport creates a world writable lock file with root ownership in the world writable /var/lock/apport directory. If the apport/ directory does not exist (this is not uncommon as /var/lock is a tmpfs), it will create the directory, otherwise…
- CVE-2015-3147MEDIUMCVSS 6.5EG 6.52020-01-14
daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-upload, allows local users to write to arbitrary files or possibly have other unspecified impact via a symlink attack on …
- CVE-2019-1425MEDIUMCVSS 6.5EG 6.52019-11-12
An elevation of privilege vulnerability exists when Visual Studio fails to properly validate hardlinks while extracting archived files, aka 'Visual Studio Elevation of Privilege Vulnerability'.
- CVE-2010-0398MEDIUMCVSS 6.5EG 6.52019-10-30
The init script in autokey before 0.61.3-2 allows local attackers to write to arbitrary files via a symlink attack.
- CVE-2018-15351MEDIUMCVSS 6.5EG 6.52018-08-17
Denial of service via crafting malicious link and sending it to a privileged user can cause Denial of Service in Kraftway 24F2XG Router firmware version 3.5.30.1118.
- CVE-2018-14335MEDIUMCVSS 6.5EG 6.52018-07-24
An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of their permissions) via a symlink to a fake database file.
- CVE-2005-0587MEDIUMCVSS 6.5EG 6.52005-03-25
Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to overwrite arbitrary files by tricking the user into downloading a .LNK (link) file twice, which overwrites the file that was referenced in the first .LNK fi…
- CVE-2025-43448MEDIUMCVSS 6.3EG 6.52025-11-04
This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26…
- CVE-2026-47699MEDIUMCVSS 6.4EG 6.42026-08-18
Confidential Containers Guest Components provides guest tools and components for confidential container workloads. From 0.16.0 until 0.20.0, a crafted OCI image layer can make image_rs::stream::unpack::unpack() create a hardlink outside it…
- CVE-2026-32282MEDIUMCVSS 6.4EG 6.42026-04-08
On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently igno…
- CVE-2023-6335MEDIUMCVSS 6.4EG 6.42024-01-16
Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on Windows allows User-Controlled Filename.This issue affects Workforce Access: before 8.7.
- CVE-2021-35937MEDIUMCVSS 6.4EG 6.42022-08-25
A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threa…
- CVE-2019-1002101MEDIUMCVSS 6.4EG 6.42019-04-01
The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes creates a tar inside the container, copies it over the network, and kubectl unpacks it on the user’s machine.…
- CVE-2017-7549MEDIUMCVSS 6.4EG 6.42017-09-21
A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy script…
- CVE-2014-9512MEDIUMCVSS v2 6.4EG 6.42015-02-12
rsync 3.1.1 allows remote attackers to write to arbitrary files via a symlink attack on a file in the synchronization path.
- CVE-2008-3456MEDIUMCVSS v2 6.4EG 6.42008-08-04
phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from using frames that point to pages in other domains, which makes it easier for remote attackers to conduct spoofing or phishing activities via a cross-site framing attack.
- CVE-2007-6692MEDIUMCVSS v2 6.4EG 6.42008-01-17
Open redirect vulnerability in Menalto Gallery before 2.2.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) Core and (2) print modules.
- CVE-2007-5695MEDIUMCVSS v2 6.4EG 6.42007-10-29
Open redirect vulnerability in command.php in SiteBar 3.3.8 allows remote attackers to redirect users to arbitrary web sites via a URL in the forward parameter in a Log In action.
- CVE-2026-108119MEDIUMCVSS 6.3EG 6.32026-10-09
A flaw was found in busybox. The tar applet's deferred link-creation handling for symlink and hardlink entries with unsafe-looking targets does not validate that the resolved destination remains inside the extraction directory once the def…
- CVE-2026-90807MEDIUMCVSS 6.3EG 6.32026-09-14
A vulnerability was found in nanocoai NanoClaw up to 2.1.17. This issue affects the function forwardAttachedFiles of the file src/modules/agent-to-agent/agent-route.ts of the component Attachment Handler. The manipulation results in link f…
- CVE-2026-89258MEDIUMCVSS 6.3EG 6.32026-09-11
Hugo is a static site generator. In versions after v0.123.0 and before v0.165.0, symlinks in parent directories were not dropped during direct resource lookups, allowing path confinement to be bypassed. An attacker who can place — or who…
- CVE-2026-53799MEDIUMCVSS 6.3EG 6.32026-08-13
rsync before 3.5.0 contains a symlink race condition vulnerability that allows local attackers to cause rsync to apply arbitrary ACLs or extended attributes to unintended files by substituting a symlink at a predictable destination path b…
- CVE-2026-53796MEDIUMCVSS 6.3EG 6.32026-08-13
rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the non-daemon receiver's destination directory handling that allows an attacker who can manipulate destination path parent components to …
- CVE-2026-19008MEDIUMCVSS 6.3EG 6.32026-08-06
A vulnerability was identified in mf-yang openclaw-cn up to 0.2.1. This issue affects the function assertNoSymlinkEscape of the file src/agents/sandbox-paths.ts of the component apply_patch Tool. Such manipulation leads to link following. …
- CVE-2026-15629MEDIUMCVSS 6.3EG 6.32026-07-14
A weakness has been identified in louisho5 picobot up to 0.2.0. Impacted is the function CreateSkill/GetSkill of the file internal/agent/tools/filesystem.go of the component Workspace Handler. Executing a manipulation can lead to link foll…
- CVE-2026-55668MEDIUMCVSS 6.3EG 6.32026-07-08
File Browser provides a web file managing interface. Prior to 2.63.16, ScopedFs validates the nearest existing ancestor of a dangling symlink as in scope and then follows the symlink during file creation, allowing an authenticated user wit…
- CVE-2026-44275MEDIUMCVSS 6.3EG 6.32026-06-09
Dell/Alienware Purchased Apps, versions prior to 1.1.32.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, l…
- CVE-2026-43619MEDIUMCVSS 6.3EG 6.32026-05-20
Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to redirect …
Map vulnerabilities like CWE-59 to your infrastructure
EchelonGraph correlates every CVE — across CWE-59 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →