CWE-59— Improper Link Resolution Before File Access (Link Following)
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.— MITRE CWE catalog
1,750 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-59page 27 of 35
- CVE-2026-2490MEDIUMCVSS 5.5EG 5.52026-02-20
RustDesk Client for Windows Transfer File Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of RustDesk Client for Windows. An attacke…
- CVE-2025-13154MEDIUMCVSS 5.5EG 5.52026-01-14
An improper link following vulnerability was reported in the SmartPerformanceAddin for Lenovo Vantage that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges.
- CVE-2025-43461MEDIUMCVSS 5.5EG 5.52025-12-12
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Tahoe 26.1. An app may be able to access protected user data.
- CVE-2025-43381MEDIUMCVSS 5.5EG 5.52025-12-12
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Tahoe 26.1. A malicious app may be able to delete protected user data.
- CVE-2025-59510MEDIUMCVSS 5.5EG 5.52025-11-11
Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service locally.
- CVE-2025-43446MEDIUMCVSS 5.5EG 5.52025-11-04
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to modify protected parts of the file system.
- CVE-2025-43394MEDIUMCVSS 5.5EG 5.52025-11-04
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access protected user data.
- CVE-2025-43379MEDIUMCVSS 5.5EG 5.52025-11-04
This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. An app may be able to acce…
- CVE-2025-43288MEDIUMCVSS 5.5EG 5.52025-11-04
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An app may be able to bypass Privacy preferences.
- CVE-2025-58373MEDIUMCVSS 5.5EG 5.52025-09-05
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vulnerability where .rooignore protections could be bypassed using symlinks. This allows an attacker with write access to …
- CVE-2024-54554MEDIUMCVSS 5.5EG 5.52025-08-29
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be able to access sensitive user data.
- CVE-2025-30642MEDIUMCVSS 5.5EG 5.52025-06-17
A link following vulnerability in Trend Micro Deep Security 20.0 agents could allow a local attacker to create a denial of service (DoS) situation on affected installations. Please note: an attacker must first obtain the ability to exec…
- CVE-2025-0913MEDIUMCVSS 5.5EG 5.52025-06-11
os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a dangling symlink. On Unix systems, OpenFile with O_CREATE and O_EXCL flags never follows symlinks. On Windows, when the target…
- CVE-2025-31198MEDIUMCVSS 5.5EG 5.52025-05-29
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A path handling issue was addressed with improved validation.
- CVE-2025-29837MEDIUMCVSS 5.5EG 5.52025-05-13
Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to disclose information locally.
- CVE-2025-24104MEDIUMCVSS 5.5EG 5.52025-01-27
This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4. Restoring a maliciously crafted backup file may lead to modification of protected system files.
- CVE-2025-24103MEDIUMCVSS 5.5EG 5.52025-01-27
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to access protected user data.
- CVE-2025-21274MEDIUMCVSS 5.5EG 5.52025-01-14
Windows Event Tracing Denial of Service Vulnerability
- CVE-2024-12754MEDIUMCVSS 5.5EG 5.52024-12-30
AnyDesk Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privile…
- CVE-2024-56074MEDIUMCVSS 5.5EG 5.52024-12-15
gitingest before 9996a06 mishandles symbolic links that point outside of the base directory.
- CVE-2024-7236MEDIUMCVSS 5.5EG 5.52024-11-22
AVG AntiVirus Free icarus Arbitrary File Creation Denial of Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AVG AntiVirus Free. An attacker must first ob…
- CVE-2024-44273MEDIUMCVSS 5.5EG 5.52024-10-28
This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. A malicious app may be able to access private inf…
- CVE-2024-44264MEDIUMCVSS 5.5EG 5.52024-10-28
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious app may be able to create symlinks to protected regions of the disk.
- CVE-2024-44175MEDIUMCVSS 5.5EG 5.52024-10-28
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7.1. An app may be able to access sensitive user data.
- CVE-2024-45315MEDIUMCVSS 5.5EG 5.52024-10-11
The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12.4.3.271 and earlier of Windows client) allows users with standard privileges to create arbitrary folders and files, po…
- CVE-2024-43603MEDIUMCVSS 5.5EG 5.52024-10-08
Visual Studio Collector Service Denial of Service Vulnerability
- CVE-2024-44178MEDIUMCVSS 5.5EG 5.52024-09-17
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. An app may be able to modify protected parts of the file system.
- CVE-2024-44131MEDIUMCVSS 5.5EG 5.52024-09-17
This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to access sensitive user data.
- CVE-2024-30065MEDIUMCVSS 5.5EG 5.52024-06-11
Windows Themes Denial of Service Vulnerability
- CVE-2024-0068MEDIUMCVSS 5.5EG 5.52024-02-29
Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows File Manipulation.This issue affects Workforce Access: before 8.7.1.
- CVE-2023-51654MEDIUMCVSS 5.5EG 5.52023-12-26
Improper link resolution before file access ('Link Following') issue exists in iPrint&Scan Desktop for Windows versions 11.0.0 and earlier. A symlink attack by a malicious user may cause a Denial-of-service (DoS) condition on the PC.
- CVE-2023-41968MEDIUMCVSS 5.5EG 5.52023-09-27
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.6, tvOS 17, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to read arbitrary files.
- CVE-2023-32556MEDIUMCVSS 5.5EG 5.52023-06-26
A link following vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to disclose sensitive information. Please note: an attacker must first obtain the ability to execute low-privileged …
- CVE-2023-24577MEDIUMCVSS 5.5EG 5.52023-03-13
McAfee Total Protection prior to 16.0.50 allows attackers to elevate user privileges due to Improper Link Resolution via registry keys. This could enable a user with lower privileges to execute unauthorized tasks.
- CVE-2022-22582MEDIUMCVSS 5.5EG 5.52023-02-27
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Security Update 2022-003 Catalina, macOS Big Sur 11.6.5, macOS Monterey 12.3. A local user may be…
- CVE-2023-22490MEDIUMCVSS 5.5EG 5.52023-02-14
Git is a revision control system. Using a specially-crafted repository, Git prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8 can be tricked into using its local clone optimization even wh…
- CVE-2022-39253MEDIUMCVSS 5.5EG 5.52022-10-19
Git is an open source, scalable, distributed revision control system. Versions prior to 2.30.6, 2.31.5, 2.32.4, 2.33.5, 2.34.5, 2.35.5, 2.36.3, and 2.37.4 are subject to exposure of sensitive information to a malicious actor. When performi…
- CVE-2022-0029MEDIUMCVSS 5.5EG 5.52022-09-14
An improper link resolution vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local attacker to read files on the system with elevated privileges when generating a tech support file.
- CVE-2022-35631MEDIUMCVSS 5.5EG 5.52022-07-29
On MacOS and Linux, it may be possible to perform a symlink attack by replacing this predictable file name with a symlink to another file and have the Velociraptor client overwrite the other file. This issue was resolved in Velociraptor 0.…
- CVE-2021-23521MEDIUMCVSS 5.5EG 5.52022-01-31
This affects the package juce-framework/JUCE before 6.1.5. This vulnerability is triggered when a malicious archive is crafted with an entry containing a symbolic link. When extracted, the symbolic link is followed outside of the target di…
- CVE-2021-1612MEDIUMCVSS 5.5EG 5.52021-09-23
A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to overwrite arbitrary files on the local system. This vulnerability is due to improper access controls on files within the local file sys…
- CVE-2021-30968MEDIUMCVSS 5.5EG 5.52021-08-24
A validation issue related to hard link behavior was addressed with improved sandbox restrictions. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, wa…
- CVE-2021-30855MEDIUMCVSS 5.5EG 5.52021-08-24
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, iOS 15 and iPadOS 15, watchOS 8, mac…
- CVE-2021-27851MEDIUMCVSS 5.5EG 5.52021-04-26
A security vulnerability that can lead to local privilege escalation has been found in ’guix-daemon’. It affects multi-user setups in which ’guix-daemon’ runs locally. The attack consists in having an unprivileged user spawn a buil…
- CVE-2021-28650MEDIUMCVSS 5.5EG 5.52021-03-17
autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex s…
- CVE-2020-4717MEDIUMCVSS 5.5EG 5.52021-03-10
A vulnerability exists in IBM SPSS Modeler Subscription Installer that allows a user with create symbolic link permission to write arbitrary file in another protected path during product installation. IBM X-Force ID: 187727.
- CVE-2021-24084MEDIUMCVSS 5.5EG 5.52021-02-25
Windows Mobile Device Management Information Disclosure Vulnerability
- CVE-2020-36241MEDIUMCVSS 5.5EG 5.52021-02-05
autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outs…
- CVE-2020-8585MEDIUMCVSS 5.5EG 5.52021-01-28
OnCommand Unified Manager Core Package versions prior to 5.2.5 may disclose sensitive account information to unauthorized users via the use of PuTTY Link (plink).
- CVE-2020-28935MEDIUMCVSS 5.5EG 5.52020-12-07
NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including version 4.3.3, contain a local vulnerability that would allow for a local symlink attack. When writing the PID file, Unbound and NSD create the…
Map vulnerabilities like CWE-59 to your infrastructure
EchelonGraph correlates every CVE — across CWE-59 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →