CWE-59— Improper Link Resolution Before File Access (Link Following)
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.— MITRE CWE catalog
1,750 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-59page 26 of 35
- CVE-2022-38699MEDIUMCVSS 5.9EG 5.92022-09-28
Armoury Crate Service’s logging function has insufficient validation to check if the log file is a symbolic link. A physical attacker with general user privilege can modify the log file property to a symbolic link that points to arbitrar…
- CVE-2019-13636MEDIUMCVSS 5.9EG 5.92019-07-17
In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. This affects inp.c and util.c.
- CVE-2018-1196MEDIUMCVSS 5.9EG 5.92018-03-19
Spring Boot supports an embedded launch script that can be used to easily run the application as a systemd or init.d linux service. The script included with Spring Boot 1.5.9 and earlier and 2.0.0.M1 through 2.0.0.M7 is susceptible to a sy…
- CVE-2026-87798MEDIUMCVSS 5.8EG 5.82026-09-28
Improper link resolution in the recursive file pull feature of the LXD CLI client in Canonical LXD versions 4.0.2 up to 6.9 (fixed in 4.0.14, 5.0.10 and 5.21.8) on Linux allows an attacker with root access inside a virtual machine to write…
- CVE-2026-54576MEDIUMCVSS 5.8EG 5.82026-09-17
mport is the MidnightBSD Package Manager. Prior to 2.7.8, do_actual_install() in libmport/bundle_read_install_pkg.c used path-based lstat(), chown(), stat(), and chmod() operations while installing package files. A local attacker with writ…
- CVE-2026-54587MEDIUMCVSS 5.8EG 5.82026-09-17
mport is the MidnightBSD Package Manager. Prior to 2.7.8, directory assets handled as ASSET_DIR or ASSET_DIR_OWNER_MODE in libmport/bundle_read_install_pkg.c used path-based mport_mkdirp(), ownership, and permission operations. A local att…
- CVE-2026-67433MEDIUMCVSS 5.8EG 5.82026-07-29
Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In version 6.0.0, the logfile check legacy database migration moved a predictable path from /tmp with os.rename() and all…
- CVE-2015-1038MEDIUMCVSS v2 5.8EG 5.82015-01-21
p7zip 9.20.1 allows remote attackers to write to arbitrary files via a symlink attack in an archive.
- CVE-2013-6456MEDIUMCVSS v2 5.8EG 5.82014-04-15
The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDettach API and a symlink attack on /dev in the container; (2) create arbitrary nodes (mknod) v…
- CVE-2010-3879MEDIUMCVSS v2 5.8EG 5.82011-01-22
FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent directory of the mountpoint of a FUSE filesystem, a different…
- CVE-2008-4284MEDIUMCVSS v2 5.8EG 5.82009-02-10
Open redirect vulnerability in the ibm_security_logout servlet in IBM WebSphere Application Server (WAS) 5.1.1.19 and earlier 5.x versions, 6.0.x before 6.0.2.33, and 6.1.x before 6.1.0.23 allows remote attackers to redirect users to arbit…
- CVE-2009-0347MEDIUMCVSS v2 5.8EG 5.82009-01-29
Open redirect vulnerability in cs.html in the Autonomy (formerly Verity) Ultraseek search engine allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the url parameter.
- CVE-2007-5437MEDIUMCVSS v2 5.8EG 5.82007-10-13
The web console in CA (formerly Computer Associates) eTrust ITM (Threat Manager) 8.1 allows remote attackers to redirect users to arbitrary web sites via a crafted HTTP URL on port 6689.
- CVE-2026-87910MEDIUMCVSS 5.7EG 5.72026-09-11
When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the locati…
- CVE-2025-2102MEDIUMCVSS 5.7EG 5.72025-05-21
Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Passwordless on Windows allows Privilege Escalation.This issue affects HYPR Passwordless: before 10.1.
- CVE-2019-3698MEDIUMCVSS 5.7EG 5.72020-02-28
UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially escalate…
- CVE-2026-88265MEDIUMCVSS 5.6EG 5.62026-09-10
A flaw was found in crun. After pivot_root, reopening /dev/null for stdio can follow a symlink and attach a host file to container stdio, then change that file's ownership. Affected versions are crun 1.29.1 and earlier. Default configurati…
- CVE-2026-88264MEDIUMCVSS 5.6EG 5.62026-09-10
A flaw was found in crun. When the container configuration does not give /dev a dedicated mount, terminal setup can redirect /dev/console onto an attacker-controlled path, including via the read-only-rootfs bind-mount fallback. Affected ve…
- CVE-2025-12418MEDIUMCVSS 5.6EG 5.62025-11-07
Potential Denial of Service issue in all supported versions of Revenera InstallShield version 2025 R1, 2024 R2, 2023 R2, and prior. When e.g., a local administrator performs an uninstall, a symlink may get followed on removal of a user wri…
- CVE-2020-3432MEDIUMCVSS 5.6EG 5.62025-02-12
A vulnerability in the uninstaller component of Cisco AnyConnect Secure Mobility Client for Mac OS could allow an authenticated, local attacker to corrupt the content of any file in the filesystem. The vulnerability is due to the incorrec…
- CVE-2023-21567MEDIUMCVSS 5.6EG 5.62023-02-14
Visual Studio Denial of Service Vulnerability
- CVE-2012-3440MEDIUMCVSS v2 5.6EG 5.62012-08-08
A certain Red Hat script for sudo 1.7.2 on Red Hat Enterprise Linux (RHEL) 5 allows local users to overwrite arbitrary files via a symlink attack on the /var/tmp/nsswitch.conf.bak temporary file.
- CVE-2012-3345MEDIUMCVSS v2 5.6EG 5.62012-06-15
ioquake3 before r2253 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/ioq3.pid temporary file.
- CVE-2026-107608MEDIUMCVSS 5.5EG 5.52026-10-08
Improper link resolution before file access in the asset bundling output handling in AWS aws-cdk-lib before 2.267.0 might allow a context-dependent actor to cause files from the build host to be published as the deployed asset. To remed…
- CVE-2026-76061MEDIUMCVSS 5.5EG 5.52026-10-06
A flaw was found in CRI-O's `bind_mount_prefix` handling. When configured with a non-empty `bind_mount_prefix`, a malicious container or local attacker could use a Container Runtime Interface (CRI) hostPath containing an intermediate absol…
- CVE-2026-68830MEDIUMCVSS 5.5EG 5.52026-09-08
Improper link resolution before file access ('link following') in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally.
- CVE-2026-72971MEDIUMCVSS 5.5EG 5.52026-08-11
Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.
- CVE-2026-70348MEDIUMCVSS 5.5EG 5.52026-08-11
Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.
- CVE-2026-15059MEDIUMCVSS 5.5EG 5.52026-08-10
Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation.
- CVE-2026-43765MEDIUMCVSS 5.5EG 5.52026-07-27
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to modify protected parts of the file system.
- CVE-2026-65065MEDIUMCVSS 5.5EG 5.52026-07-21
Data::RoaringBitmap::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in roaring.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so …
- CVE-2026-58414MEDIUMCVSS 5.5EG 5.52026-07-20
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.backup()` recursively collects files using `_collectBackupFiles()`. `_collectBackupFiles()` uses `statSync(full)`, which follows syml…
- CVE-2026-50526MEDIUMCVSS 5.5EG 5.52026-07-14
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
- CVE-2026-49180MEDIUMCVSS 5.5EG 5.52026-07-14
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
- CVE-2026-15681MEDIUMCVSS 5.5EG 5.52026-07-13
AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to e…
- CVE-2026-15682MEDIUMCVSS 5.5EG 5.52026-07-13
AnyDesk Support Information Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability t…
- CVE-2026-58198MEDIUMCVSS 5.5EG 5.52026-07-09
ChatterBot is a machine learning, conversational dialog engine for creating chat bots. Prior to 1.2.14, UbuntuCorpusTrainer.extract() uses a predictable home-rooted output directory (~/ubuntu_data/ubuntu_dialogs) with a check-then-create p…
- CVE-2026-39243MEDIUMCVSS 5.5EG 5.52026-07-09
decompress before 4.2.2 allows arbitrary hardlink creation during archive extraction, enabling file read disclosure and file corruption. When processing hardlink entries (type === 'link'), the x.linkname field from the archive is passed di…
- CVE-2026-56692MEDIUMCVSS 5.5EG 5.52026-06-23
NanoClaw before 2.1.17 contains a symlink following vulnerability in forwardAttachedFiles that allows container-controlled agents to exfiltrate host-readable files. The host validates attachment filenames using only isSafeAttachmentName be…
- CVE-2026-55443MEDIUMCVSS 5.5EG 5.52026-06-22
LangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components that resolve filesystem paths or expand search patterns do not consistently confine the resolved path to the intended r…
- CVE-2026-50135MEDIUMCVSS 5.5EG 5.52026-06-16
Hugo is a static site generator. From 0.123.0 to 0.161.1, a regression made RootMappingFs.statRoot use Stat (follows symlinks) instead of Lstat , so a direct resources.Get of a symlink pointing outside its mount returned the…
- CVE-2025-46293MEDIUMCVSS 5.5EG 5.52026-06-11
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.
- CVE-2026-45491MEDIUMCVSS 5.5EG 5.52026-06-09
Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally.
- CVE-2026-48693MEDIUMCVSS 5.5EG 5.52026-05-26
FastNetMon Community Edition through 1.2.9 is vulnerable to a local symlink attack via predictable file paths in /tmp. The statistics file path defaults to '/tmp/fastnetmon.dat' (src/fastnetmon.cpp line 159). The print_screen_contents_into…
- CVE-2026-40610MEDIUMCVSS 5.5EG 5.52026-05-22
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1.4.38 and prior, the build packaging workflow follows attacker-controlled symlinks inside the build context and copies …
- CVE-2026-20161MEDIUMCVSS 5.5EG 5.52026-04-15
A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent could allow an authenticated, local attacker with low privileges to overwrite arbitrary files on the local system of an affected device. This vulnerability is due to impr…
- CVE-2026-32212MEDIUMCVSS 5.5EG 5.52026-04-14
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
- CVE-2026-20694MEDIUMCVSS 5.5EG 5.52026-03-25
This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.4, macOS Sonoma 14.8.5, macOS Tahoe 26.3, macOS Tahoe 26.4. An app …
- CVE-2026-20633MEDIUMCVSS 5.5EG 5.52026-03-25
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access user-sensitive data.
- CVE-2026-32024MEDIUMCVSS 5.5EG 5.52026-03-19
OpenClaw versions prior to 2026.2.22 contain a symlink traversal vulnerability in avatar handling that allows attackers to read arbitrary files outside the configured workspace boundary. Remote attackers can exploit this by requesting avat…
Map vulnerabilities like CWE-59 to your infrastructure
EchelonGraph correlates every CVE — across CWE-59 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →