CWE-59— Improper Link Resolution Before File Access (Link Following)
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.— MITRE CWE catalog
1,746 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-59page 5 of 35
- CVE-2021-32803HIGHCVSS 8.2EG 8.22021-08-03
The npm package "tar" (aka node-tar) before versions 6.1.2, 5.0.7, 4.4.15, and 3.2.3 has an arbitrary File Creation/Overwrite vulnerability via insufficient symlink protection. `node-tar` aims to guarantee that any file whose location woul…
- CVE-2021-23892HIGHCVSS 8.2EG 8.22021-05-12
By exploiting a time of check to time of use (TOCTOU) race condition during the Endpoint Security for Linux Threat Prevention and Firewall (ENSL TP/FW) installation process, a local user can perform a privilege escalation attack to obtain …
- CVE-2020-7250HIGHCVSS 8.2EG 8.22020-04-15
Symbolic link manipulation vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2020 Update allows authenticated local user to potentially gain an escalation of privileges by pointing the link to files which…
- CVE-2011-1408HIGHCVSS 8.2EG 8.22019-10-29
ikiwiki before 3.20110608 allows remote attackers to hijack root's tty and run symlink attacks.
- CVE-2026-107810HIGHCVSS 8.1EG 8.12026-10-09
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, internal/backup/restore.go extracts inner archives before applying the restore_nginx and restore_nginx_ui flags and permits symlinks targeting the live Ngin…
- CVE-2026-100838HIGHCVSS 8.1EG 8.12026-09-27
Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata agent policies generated by the Contrast CLI contained a flaw in the CopyFile verification that allowed arbitrary writes to the guest root fil…
- CVE-2026-70563HIGHCVSS 8.1EG 8.12026-09-08
Improper link resolution before file access ('link following') in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-19693HIGHCVSS 8.1EG 8.12026-08-17
extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the …
- CVE-2026-70460HIGHCVSS 8.1EG 8.12026-08-13
rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options. Attackers with …
- CVE-2026-53795HIGHCVSS 8.1EG 8.12026-08-13
rsync before 3.5.0 contains an arbitrary file write vulnerability that allows attackers to write files outside the intended destination tree by specifying an absolute path via --temp-dir or --link-dest options. The rename-confinement logi…
- CVE-2026-53783HIGHCVSS 8.1EG 8.12026-08-13
rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to escape enforced directory restrictions by substituting a symlink …
- CVE-2026-35025HIGHCVSS 8.1EG 8.12026-06-24
ProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass vulnerability that allows authenticated FTP users to circumvent Directory ACL restrictions by prefixing paths with /proc/self/root in the RNFR command handler. Attacker…
- CVE-2026-44051HIGHCVSS 8.1EG 8.12026-05-21
An improper link resolution vulnerability in Netatalk 3.0.2 through 4.4.2 allows a remote authenticated attacker to read arbitrary files or overwrite arbitrary files via attacker-controlled symlink creation.
- CVE-2026-41364HIGHCVSS 8.1EG 8.12026-04-28
OpenClaw before 2026.3.31 contains a symlink following vulnerability in SSH sandbox tar upload that allows remote attackers to write arbitrary files. Attackers can exploit this by uploading tar archives containing symlinks to escape the sa…
- CVE-2025-15314HIGHCVSS 8.1EG 8.12026-02-10
Tanium addressed an arbitrary file deletion vulnerability in end-user-cx.
- CVE-2023-28868HIGHCVSS 8.1EG 8.12023-12-09
Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to delete arbitrary files on the operating system by creating a symbolic link.
- CVE-2023-46654HIGHCVSS 8.1EG 8.12023-10-25
Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the expected directory during the cleanup process of the 'CloudBees CD - Publish Artifact' post-build step, allowing attackers able to configure …
- CVE-2023-29351HIGHCVSS 8.1EG 8.12023-06-14
Windows Group Policy Elevation of Privilege Vulnerability
- CVE-2022-36943HIGHCVSS 8.1EG 8.12023-01-03
SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths which are symlinks. SSZipArchive will overwrite files on the filesystem when opening a malicious ZIP containing a syml…
- CVE-2021-21686HIGHCVSS 8.1EG 8.12021-11-04
File path filters in the agent-to-controller security subsystem of Jenkins 2.318 and earlier, LTS 2.303.2 and earlier do not canonicalize paths, allowing operations to follow symbolic links to outside allowed directories.
- CVE-2021-41072HIGHCVSS 8.1EG 8.12021-09-14
squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link and then contents under the same filen…
- CVE-2021-30356HIGHCVSS 8.1EG 8.12021-04-22
A denial of service vulnerability was reported in Check Point Identity Agent before R81.018.0000, which could allow low privileged users to overwrite protected system files.
- CVE-2021-21125HIGHCVSS 8.1EG 8.12021-02-09
Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.
- CVE-2020-25744HIGHCVSS 8.1EG 8.12020-09-18
SaferVPN before 5.0.3.3 on Windows could allow low-privileged users to create or overwrite arbitrary files, which could cause a denial of service (DoS) condition, because a symlink from %LOCALAPPDATA%\SaferVPN\Log is followed.
- CVE-2020-11443HIGHCVSS 8.1EG 8.12020-05-04
The Zoom IT installer for Windows (ZoomInstallerFull.msi) prior to version 4.6.10 deletes files located in %APPDATA%\Zoom before installing an updated version of the client. Standard users are able to write to this directory, and can write…
- CVE-2020-7040HIGHCVSS 8.1EG 8.12020-01-21
storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege escalation. (Local users can also create a plain file named /tmp/storeBackup.lock to block…
- CVE-2019-3567HIGHCVSS 8.1EG 8.12019-06-03
In some configurations an attacker can inject a new executable path into the extensions.load file for osquery and hard link a parent folder of a malicious binary to a folder with known 'safe' permissions. Under those circumstances osquery …
- CVE-2018-10897HIGHCVSS 8.1EG 8.12018-08-01
A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration files. If an attacker controls a repository, they may be able to copy files outside of the de…
- CVE-2018-13054HIGHCVSS 8.1EG 8.12018-07-02
An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs as root and allows configuration of (for example) other users' icon files in _on_face_browse_menuitem_activated and _on_face_menuitem_activate…
- CVE-2021-44052HIGHCVSS 6.5EG 8.12022-05-05
An improper link resolution before file access ('Link Following') vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, and QTS. If exploited, this vulnerability allows remote attackers to traverse the file sy…
- CVE-2026-23879HIGHCVSS 8.0EG 8.02026-06-19
py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Versions 1.1.2 and below contain an an arbitrary file write vulnerability, which allows symbolic links to be recreat…
- CVE-2026-44711HIGHCVSS 7.9EG 7.92026-05-27
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, symlink attacks on pad directory and pad files enable authentication bypass and root file corruption. This vulnerability is fixed in 0.8.7.
- CVE-2024-29188HIGHCVSS 7.9EG 7.92024-03-24
WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. The custom action behind WiX's `RemoveFolderEx` functionality could allow a standard user to delete protected directories. `RemoveFolderE…
- CVE-2022-31466HIGHCVSS 7.9EG 7.92022-05-23
Time of Check - Time of Use (TOCTOU) vulnerability in Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escalation, potentially leading to deletion of system files. This is achieved through exploitin…
- CVE-2026-107707HIGHCVSS 7.8EG 7.82026-10-08
Intego Antivirus for Windows through 3.0.0.1 contains a link following vulnerability in its optimization module that allows local unprivileged users to delete arbitrary folders as SYSTEM. Attackers can replace a scanned duplicate file's di…
- CVE-2026-102113HIGHCVSS 7.8EG 7.82026-09-30
A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root. A privileged routine did not safely handle a…
- CVE-2026-102118HIGHCVSS 7.8EG 7.82026-09-30
A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an existing shell under a low-privileged service account to escalate to root privileges on the appliance.
- CVE-2026-69289HIGHCVSS 7.8EG 7.82026-09-08
Improper link resolution before file access ('link following') in Windows Setup Files Cleanup allows an authorized attacker to elevate privileges locally.
- CVE-2026-19820HIGHCVSS 7.8EG 7.82026-09-01
A vulnerability in the Backblaze Client allows a local user to make the system not bootable by creating a link from Backblaze's folder to Windows OS system files during a backup. Successful exploitation requires an administrator-level syst…
- CVE-2026-81572HIGHCVSS 7.8EG 7.82026-08-27
In CodeMeter Runtime from version 8.40 to (excluding) 8.41a and 9.00 to (excluding) 9.10, cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and file paths are not properly checked for NTFS …
- CVE-2026-79655HIGHCVSS 7.8EG 7.82026-08-25
A flaw was found in sos clean, a utility within the sos package. This vulnerability allows a local attacker to perform arbitrary file creation or overwrite. By crafting a malicious tar archive, an attacker can exploit a path traversal issu…
- CVE-2026-17171HIGHCVSS 7.8EG 7.82026-08-20
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite arbitrary files due to improper resolution of symbolic links.
- CVE-2026-16989HIGHCVSS 7.8EG 7.82026-08-20
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper resolution of symbolic links.
- CVE-2026-53803HIGHCVSS 7.8EG 7.82026-08-13
rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable output path such as --log-file, --write-batch, or daemon-mode log and statistics p…
- CVE-2026-62832HIGHCVSS 7.8EG 7.82026-08-11
Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-62807HIGHCVSS 7.8EG 7.82026-08-11
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
- CVE-2026-62803HIGHCVSS 7.8EG 7.82026-08-11
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
- CVE-2026-62776HIGHCVSS 7.8EG 7.82026-08-11
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
- CVE-2026-62761HIGHCVSS 7.8EG 7.82026-08-11
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
- CVE-2026-61358HIGHCVSS 7.8EG 7.82026-08-11
Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.
Map vulnerabilities like CWE-59 to your infrastructure
EchelonGraph correlates every CVE — across CWE-59 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →