CWE-59— Improper Link Resolution Before File Access (Link Following)
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.— MITRE CWE catalog
1,750 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-59page 25 of 35
- CVE-2026-53766MEDIUMCVSS 6.1EG 6.12026-06-24
Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From 0.24.0 until 1.1.0, McpContext.validatePath() enforces workspace roots by checking whether path.resolve(filePath) textu…
- CVE-2026-56236MEDIUMCVSS 6.1EG 6.12026-06-21
Capgo CLI before 12.128.2 contains arbitrary file overwrite vulnerabilities in login and build credentials operations that follow symlinks without validation. Attackers can create malicious symlinks in repositories to overwrite arbitrary f…
- CVE-2026-47833MEDIUMCVSS 6.1EG 6.12026-06-18
setupBpmLogs follows symlink for bpm.log open and chown — container-to-host privilege escalation via /etc/shadow. A compromised process inside a bpm container can cause root to chown an arbitrary host file to vcap and append bpm JSON log…
- CVE-2026-53765MEDIUMCVSS 6.1EG 6.12026-06-17
Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From 0.20.0 until 1.1.0, The chrome-devtools-mcp daemon writes its PID file with fs.writeFileSync() to a deterministic runti…
- CVE-2026-45384MEDIUMCVSS 6.1EG 6.12026-06-10
bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4.0.12, there is an arbitrary file overwrite vulnerability via symlink attack on predictable temp files during archive u…
- CVE-2026-47121MEDIUMCVSS 6.1EG 6.12026-05-29
Sparkle is a software update framework for macOS. Prior to version 2.9.2, `Autoupdate/SUBinaryDeltaApply.m` enforces `relativePath.pathComponents containsObject:@".."` and rejects writes whose immediate parent directory IS itself a symboli…
- CVE-2026-31990MEDIUMCVSS 6.1EG 6.12026-03-19
OpenClaw versions prior to 2026.3.2 contain a vulnerability in the stageSandboxMedia function in which it fails to validate destination symlinks during media staging, allowing writes to follow symlinks outside the sandbox workspace. Attack…
- CVE-2025-22247MEDIUMCVSS 6.1EG 6.12025-05-12
VMware Tools contains an insecure file handling vulnerability. A malicious actor with non-administrative privileges on a guest VM may tamper the local files to trigger insecure file operations within that VM.
- CVE-2024-36306MEDIUMCVSS 6.1EG 6.12024-06-10
A link following vulnerability in the Trend Micro Apex One and Apex One as a Service Damage Cleanup Engine could allow a local attacker to create a denial-of-service condition on affected installations. Please note: an attacker must fir…
- CVE-2023-28642MEDIUMCVSS 6.1EG 6.12023-03-29
runc is a CLI tool for spawning and running containers according to the OCI specification. It was found that AppArmor can be bypassed when `/proc` inside the container is symlinked with a specific mount configuration. This issue has been f…
- CVE-2022-2898MEDIUMCVSS 6.1EG 6.12022-08-31
Measuresoft ScadaPro Server and Client (All Versions) do not properly resolve links before file access; this could allow a denial-of-service condition.
- CVE-2022-0012MEDIUMCVSS 6.1EG 6.12022-01-12
An improper link resolution before file access vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables a local user to delete arbitrary system files and impact the system integrity or cause a denia…
- CVE-2021-3641MEDIUMCVSS 6.1EG 6.12021-11-09
Improper Link Resolution Before File Access ('Link Following') vulnerability in the EPAG component of Bitdefender Endpoint Security Tools for Windows allows a local attacker to cause a denial of service. This issue affects: Bitdefender Gra…
- CVE-2021-27241MEDIUMCVSS 6.1EG 6.12021-03-29
This vulnerability allows local attackers to delete arbitrary directories on affected installations of Avast Premium Security 20.8.2429 (Build 20.8.5653.561). An attacker must first obtain the ability to execute low-privileged code on the …
- CVE-2021-26866MEDIUMCVSS 6.1EG 6.12021-03-11
Windows Update Service Elevation of Privilege Vulnerability
- CVE-2020-26277MEDIUMCVSS 6.1EG 6.12020-12-21
DBdeployer is a tool that deploys MySQL database servers easily. In DBdeployer before version 1.58.2, users unpacking a tarball may use a maliciously packaged tarball that contains symlinks to files external to the target. In such scenario…
- CVE-2020-5797MEDIUMCVSS 6.1EG 6.12020-11-21
UNIX Symbolic Link (Symlink) Following in TP-Link Archer C9(US)_V1_180125 firmware allows an unauthenticated actor, with physical access and network access, to read sensitive files and write to a limited set of files after plugging a craft…
- CVE-2013-1867MEDIUMCVSS 6.1EG 6.12020-01-30
Gemalto Tokend 2013 has an Arbitrary File Creation/Overwrite Vulnerability
- CVE-2013-1866MEDIUMCVSS 6.1EG 6.12020-01-30
OpenSC OpenSC.tokend has an Arbitrary File Creation/Overwrite Vulnerability
- CVE-2017-12258MEDIUMCVSS 6.1EG 6.12017-10-05
A vulnerability in the web-based UI of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to execute a cross-frame scripting (XFS) attack. The vulnerability exists because the affected software does not pr…
- CVE-2015-5701MEDIUMCVSS 6.1EG 6.12017-08-25
mktexlsr revision 36855, and before revision 36626 as packaged in texlive allows local users to write to arbitrary files via a symlink attack. NOTE: this vulnerability exists due to the reversion of a fix of CVE-2015-5700.
- CVE-2015-5700MEDIUMCVSS 6.1EG 6.12017-08-25
mktexlsr revision 22855 through revision 36625 as packaged in texlive allows local users to write to arbitrary files via a symlink attack.
- CVE-2008-2052MEDIUMCVSS 6.1EG 6.12008-05-02
Open redirect vulnerability in redirect.php in Bitrix Site Manager 6.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the goto parameter.
- CVE-2024-7235MEDIUMCVSS 5.5EG 6.12024-11-22
AVG AntiVirus Free Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AVG AntiVirus Free. An attacker must first obtain the ability…
- CVE-2024-7228MEDIUMCVSS 5.5EG 6.12024-11-22
Avast Free Antivirus Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Avast Free Antivirus. An attacker must first obtain the abi…
- CVE-2026-71182MEDIUMCVSS 6.0EG 6.02026-09-16
Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability,…
- CVE-2026-71181MEDIUMCVSS 6.0EG 6.02026-09-16
Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability,…
- CVE-2026-78622MEDIUMCVSS 6.0EG 6.02026-09-08
The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges. The delete operation follows the junction target, resulting in recursiv…
- CVE-2026-55828MEDIUMCVSS 6.0EG 6.02026-06-19
qbee transport is a remote access transport protocol implementation. Prior to 1.26.25, the extractTar routine uses strictly lexical path validation that does not account for on-disk symlinks created earlier in the extraction process. A cra…
- CVE-2026-28262MEDIUMCVSS 6.0EG 6.02026-06-09
Dell iDRAC Tools, versions prior to 11.4.1.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to In…
- CVE-2026-8052MEDIUMCVSS 6.0EG 6.02026-05-12
HashiCorp Nomad’s exec2 task driver prior to 0.1.2 is vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-8052) is fixed in version 0.1.2 of the …
- CVE-2026-6959MEDIUMCVSS 6.0EG 6.02026-05-12
HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-6959) is fixed in Nomad 2.0.1, 1.11.5 a…
- CVE-2025-15318MEDIUMCVSS 6.0EG 6.02026-02-09
Tanium addressed an arbitrary file deletion vulnerability in End-User Notifications Endpoint Tools.
- CVE-2025-21195MEDIUMCVSS 6.0EG 6.02025-07-08
Improper link resolution before file access ('link following') in Service Fabric allows an authorized attacker to elevate privileges locally.
- CVE-2025-21347MEDIUMCVSS 6.0EG 6.02025-02-11
Windows Deployment Services Denial of Service Vulnerability
- CVE-2025-21188MEDIUMCVSS 6.0EG 6.02025-02-11
Azure Network Watcher VM Extension Elevation of Privilege Vulnerability
- CVE-2024-25953MEDIUMCVSS 6.0EG 6.02024-03-28
Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to denial of service, informati…
- CVE-2024-25952MEDIUMCVSS 6.0EG 6.02024-03-28
Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to denial of service, informati…
- CVE-2020-14367MEDIUMCVSS 6.0EG 6.02020-08-24
A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file is created during chronyd startup while still running as the root user, and when it's opened for writing, chronyd does n…
- CVE-2008-7247MEDIUMCVSS v2 6.0EG 6.02009-11-30
sql/sql_table.cc in MySQL 5.0.x through 5.0.88, 5.1.x through 5.1.41, and 6.0 before 6.0.9-alpha, when the data home directory contains a symlink to a different filesystem, allows remote authenticated users to bypass intended access restri…
- CVE-2007-3919MEDIUMCVSS v2 6.0EG 6.02007-10-28
(1) xenbaked and (2) xenmon.py in Xen 3.1 and earlier allow local users to truncate arbitrary files via a symlink attack on /tmp/xenq-shm.
- CVE-2026-103263MEDIUMCVSS 5.9EG 5.92026-10-01
Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directo…
- CVE-2026-12345MEDIUMCVSS 5.9EG 5.92026-09-29
The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted o…
- CVE-2026-79534MEDIUMCVSS 5.9EG 5.92026-09-29
mark3labs mcp-filesystem-server v0.11.1 is vulnerable to Directory Traversal due to an improper link resolution in validatePath (filesystemserver/handler/helper.go). When filepath.EvalSymlinks returns os.IsNotExist for a dangling symlink, …
- CVE-2026-86861MEDIUMCVSS 5.9EG 5.92026-09-17
pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested path with Filemanager.check_access_permission() and then opened the file for writing with a plain open() call. CVE-2026-78…
- CVE-2026-71493MEDIUMCVSS 5.9EG 5.92026-08-21
Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, the readFile, pathExists, isDir, and matchPaths template functions in internal/config/template/parser.go use a lexical filepath.Rel ch…
- CVE-2026-53801MEDIUMCVSS 5.9EG 5.92026-08-13
rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's directory scanning logic that allows attackers to cause the sender to enumerate and transfer files outside the module root's intended subtree. Attackers wh…
- CVE-2026-53535MEDIUMCVSS 5.9EG 5.92026-07-16
Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the git-sync feature clones a user-configured Git repository into a temporary directory on the server and then writes flow, table, and connection state into i…
- CVE-2023-32182MEDIUMCVSS 5.9EG 5.92023-09-19
A Improper Link Resolution Before File Access ('Link Following') vulnerability in SUSE SUSE Linux Enterprise Desktop 15 SP5 postfix, SUSE SUSE Linux Enterprise High Performance Computing 15 SP5 postfix, SUSE openSUSE Leap 15.5 postfix.This…
- CVE-2022-43293MEDIUMCVSS 5.9EG 5.92023-04-11
Wacom Driver 6.3.46-1 for Windows was discovered to contain an arbitrary file write vulnerability via the component \Wacom\Wacom_Tablet.exe.
Map vulnerabilities like CWE-59 to your infrastructure
EchelonGraph correlates every CVE — across CWE-59 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →