CWE-59— Improper Link Resolution Before File Access (Link Following)
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.— MITRE CWE catalog
1,746 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-59page 3 of 35
- CVE-2026-67368HIGHCVSS 8.8EG 8.82026-09-08
Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network.
- CVE-2026-54572HIGHCVSS 8.8EG 8.82026-07-14
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, with -l/--links, rclone serializes symlinks as .rclonelink text objects and recreates them on a local destinatio…
- CVE-2026-50438HIGHCVSS 8.8EG 8.82026-07-14
Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
- CVE-2026-55607HIGHCVSS 8.8EG 8.82026-06-29
Claude Code is an agentic coding tool. From 2.1.38 until 2.1.163, Claude Code's worktree handling allowed creation of worktrees named ".git" and navigation to worktrees outside the sandbox context, enabling git directory confusion attacks…
- CVE-2026-45405HIGHCVSS 8.8EG 8.82026-06-26
Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:from-archive and certs:add commands extract user-supplied tar/zip archives into temporary directories without sanitizing member paths or preventing symlink traversal. GNU tar creates…
- CVE-2026-41236HIGHCVSS 8.8EG 8.82026-05-29
Froxlor is open source server administration software. Version 2.3.6 contains a symlink-following flaw in the root-owned SSH key synchronization path used for customer FTP users. The provisioning code appends public keys to `~/.ssh/authori…
- CVE-2021-47949HIGHCVSS 8.8EG 8.82026-05-10
CyberPanel 2.1 contains a command execution vulnerability that allows authenticated attackers to read arbitrary files and execute remote code by exploiting symlink attacks through the filemanager controller endpoint. Attackers can manipula…
- CVE-2026-5161HIGHCVSS 8.8EG 8.82026-04-29
Improper link resolution before file access ('link following') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus About allows Symlink Attack. This issue affects Pardus About: before 1.2.2.
- CVE-2026-32013HIGHCVSS 8.8EG 8.82026-03-19
OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in the agents.files.get and agents.files.set methods that allows reading and writing files outside the agent workspace. Attackers can exploit symlinked allowlis…
- CVE-2026-33001HIGHCVSS 8.8EG 8.82026-03-18
Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only…
- CVE-2025-49739HIGHCVSS 8.8EG 8.82025-07-08
Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network.
- CVE-2025-41668HIGHCVSS 8.8EG 8.82025-07-08
A low privileged remote attacker with file access can replace a critical file or folder used by the service security-profile to get read, write and execute access to any file on the device.
- CVE-2025-41667HIGHCVSS 8.8EG 8.82025-07-08
A low privileged remote attacker with file access can replace a critical file used by the arp-preinit script to get read, write and execute access to any file on the device.
- CVE-2025-41666HIGHCVSS 8.8EG 8.82025-07-08
A low privileged remote attacker with file access can replace a critical file used by the watchdog to get read, write and execute access to any file on the device after the watchdog has been initialized.
- CVE-2025-47181HIGHCVSS 8.8EG 8.82025-05-22
Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.
- CVE-2024-12390HIGHCVSS 8.8EG 8.82025-03-20
A vulnerability in binary-husky/gpt_academic version git 310122f allows for remote code execution. The application supports the extraction of user-provided RAR files without proper validation. The Python rarfile module, which supports syml…
- CVE-2024-10986HIGHCVSS 8.8EG 8.82025-03-20
GPT Academic version 3.83 is vulnerable to a Local File Read (LFI) vulnerability through its HotReload function. This function can download and extract tar.gz files from arxiv.org. Despite implementing protections against path traversal, t…
- CVE-2024-53691HIGHCVSS 8.8EG 8.82024-12-06
A link following vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations…
- CVE-2024-50404HIGHCVSS 8.8EG 8.82024-12-06
A link following vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations. We have already fixed …
- CVE-2024-27458HIGHCVSS 8.8EG 8.82024-10-07
A potential security vulnerability has been identified in the HP Hotkey Support software, which might allow local escalation of privilege. HP is releasing mitigation for the potential vulnerability. Customers using HP Programmable Key are …
- CVE-2024-44132HIGHCVSS 8.8EG 8.82024-09-17
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15. An app may be able to break out of its sandbox.
- CVE-2024-28916HIGHCVSS 8.8EG 8.82024-03-21
Xbox Gaming Services Elevation of Privilege Vulnerability
- CVE-2023-28872HIGHCVSS 8.8EG 8.82023-12-25
Support Assistant in NCP Secure Enterprise Client before 13.10 allows attackers to execute DLL files with SYSTEM privileges by creating a symbolic link from a %LOCALAPPDATA%\Temp\NcpSupport* location.
- CVE-2023-6069HIGHCVSS 8.8EG 8.82023-11-10
Improper Link Resolution Before File Access in GitHub repository froxlor/froxlor prior to 2.1.0.
- CVE-2023-4759HIGHCVSS 8.8EG 8.82023-09-12
Arbitrary File Overwrite in Eclipse JGit <= 6.6.0 In Eclipse JGit, all versions <= 6.6.0.202305301015-r, a symbolic link present in a specially crafted git repository can be used to write a file to locations outside the working tree when …
- CVE-2023-33245HIGHCVSS 8.8EG 8.82023-05-30
Minecraft through 1.19 and 1.20 pre-releases before 7 (Java) allow arbitrary file overwrite, and possibly code execution, via crafted world data that contains a symlink.
- CVE-2022-45412HIGHCVSS 8.8EG 8.82022-12-22
When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error message may be produced where the symlink was resolved to a string containing unitialized memory in the buffer. <br>*This bug only affects Thunderbird on Unix-b…
- CVE-2022-0799HIGHCVSS 8.8EG 8.82022-04-05
Insufficient policy enforcement in Installer in Google Chrome on Windows prior to 99.0.4844.51 allowed a remote attacker to perform local privilege escalation via a crafted offline installer file.
- CVE-2021-21695HIGHCVSS 8.8EG 8.82021-11-04
FilePath#listFiles lists files outside directories that agents are allowed to access when following symbolic links in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.
- CVE-2021-27229HIGHCVSS 8.8EG 8.82021-02-16
Mumble before 1.3.4 allows remote code execution if a victim navigates to a crafted URL on a server list and clicks on the Open Webpage text.
- CVE-2020-7319HIGHCVSS 8.8EG 8.82020-09-09
Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local users to access files which the user otherwise would not have access to via manipulating symbolic links …
- CVE-2020-15932HIGHCVSS 8.8EG 8.82020-07-24
Overwolf before 0.149.2.30 mishandles Symbolic Links during updates, causing elevation of privileges.
- CVE-2020-13095HIGHCVSS 8.8EG 8.82020-06-30
Little Snitch version 4.5.1 and older changed ownership of a directory path controlled by the user. This allowed the user to escalate to root by linking the path to a directory containing code executed by root.
- CVE-2020-10947HIGHCVSS 8.8EG 8.82020-04-17
Mac Endpoint for Sophos Central before 9.9.6 and Mac Endpoint for Sophos Home before 2.2.6 allow Privilege Escalation.
- CVE-2020-5738HIGHCVSS 8.8EG 8.82020-04-14
Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker uploads a specially crafted tar file to the HTTP /cgi-bin/upload_vpntar interface.
- CVE-2019-9949HIGHCVSS 8.8EG 8.82019-05-23
Western Digital My Cloud Cloud, Mirror Gen2, EX2 Ultra, EX2100, EX4100, DL2100, DL4100, PR2100 and PR4100 before firmware 2.31.183 are affected by a code execution (as root, starting from a low-privilege user session) vulnerability. The cg…
- CVE-2018-14651HIGHCVSS 8.8EG 8.82018-10-31
It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was incomplete. A remote, authenticated attacker could use one of these flaws to execute arbitrary code, create arbitrary file…
- CVE-2018-10928HIGHCVSS 8.8EG 8.82018-09-04
A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated attacker could use this flaw to create arbitrary symlinks p…
- CVE-2017-2916HIGHCVSS 8.8EG 8.82017-11-07
An exploitable vulnerability exists in the /api/CONFIG/restore functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packets can cause an arbitrary file to be overwritten. An attacker can send an HTTP reques…
- CVE-2013-0261HIGHCVSS 8.8EG 8.82013-03-08
A flaw was found in PackStack. A local user could exploit a symlink attack on a temporary file with a predictable name in the `/tmp` directory. This vulnerability allows the local user to overwrite arbitrary files on the system, potentiall…
- CVE-2016-9602HIGHCVSS 7.6EG 8.82018-04-26
Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to access host file system beyond the shared folder and potentially escalating their privile…
- CVE-2019-1053HIGHCVSS 6.3EG 8.82019-06-12
An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder shortcuts. An attacker who successfully exploited the vulnerability could elevate privileges by escaping a sandbox. To exploit this vulnerabilit…
- CVE-2023-7216HIGHCVSS 5.3EG 8.82024-02-05
A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive. During the extraction process, the archiver could follow symli…
- CVE-2026-65647HIGHCVSS 8.7EG 8.72026-08-26
Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root.
- CVE-2026-71476HIGHCVSS 8.7EG 8.72026-08-06
Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx self-hosted HTTP remote cache extracts downloaded cache artifacts without constraining where files are written. A maliciou…
- CVE-2026-8170HIGHCVSS 8.7EG 8.72026-07-20
The mv, cp, and rm file utilities exposed within the ExtremeXOS (EXOS) shell environment fail to safely canonicalize paths and follow symbolic links outside of the intended privilege boundary. An attacker with low-privilege CLI access can …
- CVE-2026-14891HIGHCVSS 8.7EG 8.72026-07-08
HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job submitter to bind-mount a host path into a container even when volume bind mounts are disabled, potentially leading to r…
- CVE-2025-43257HIGHCVSS 8.7EG 8.72026-04-02
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.6. An app may be able to break out of its sandbox.
- CVE-2026-102242HIGHCVSS 8.6EG 8.62026-09-29
Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 allows a remote authenticated attacker with tool execution permissions to bypass directory…
- CVE-2025-67487HIGHCVSS 8.6EG 8.62025-12-09
Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Versions 2.40.0 and below contain symbolic links (symlinks) which can be used to access files or directories outside the intended web root fo…
Map vulnerabilities like CWE-59 to your infrastructure
EchelonGraph correlates every CVE — across CWE-59 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →