CWE-61— UNIX Symbolic Link (Symlink) Following
The product, when opening a file or directory, does not sufficiently account for when the file is a symbolic link that resolves to a target outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.— MITRE CWE catalog
186 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-61page 1 of 4
- CVE-2026-54420CRITICALCVSS 8.5EG 9.0⚠ KEV2026-06-14
LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild…
- CVE-2026-39861CRITICALCVSS 10.0EG 10.02026-04-21
Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processes from creating symlinks pointing to locations outside the workspace. When Claude Code subsequently wrote to a path wit…
- CVE-2026-34078CRITICALCVSS 10.0EG 10.02026-04-07
Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the …
- CVE-2025-62596CRITICALCVSS 10.0EG 10.02025-11-06
Youki is a container runtime written in Rust. In versions 0.5.6 and below, youki’s apparmor handling performs insufficiently strict write-target validation, and when combined with path substitution during pathname resolution, can allow w…
- CVE-2025-62161CRITICALCVSS 10.0EG 10.02025-11-06
Youki is a container runtime written in Rust. In versions 0.5.6 and below, the initial validation of the source /dev/null is insufficient, allowing container escape when youki utilizes bind mounting the container's /dev/null as a file mask…
- CVE-2024-28189CRITICALCVSS 10.0EG 10.02024-04-18
Judge0 is an open-source online code execution system. The application uses the UNIX chown command on an untrusted file within the sandbox. An attacker can abuse this by creating a symbolic link (symlink) to a file outside the sandbox, all…
- CVE-2024-28185CRITICALCVSS 10.0EG 10.02024-04-18
Judge0 is an open-source online code execution system. The application does not account for symlinks placed inside the sandbox directory, which can be leveraged by an attacker to write to arbitrary files and gain code execution outside of …
- CVE-2026-63125CRITICALCVSS 9.9EG 9.92026-08-21
Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and `can_create_instances`) can execute arbitrary code as…
- CVE-2026-91099CRITICALCVSS 9.8EG 9.82026-09-16
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, infor…
- CVE-2025-23394CRITICALCVSS 9.8EG 9.82025-05-26
A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed cyrus-imapd allows escalation from cyrus to root.This issue affects openSUSE Tumbleweed cyrus-imapd before 3.8.4-2.1.
- CVE-2024-54148CRITICALCVSS 9.8EG 9.82024-12-23
Gogs is an open source self-hosted Git service. A malicious user is able to commit and edit a crafted symlink file to a repository to gain SSH access to the server. The vulnerability is fixed in 0.13.1.
- CVE-2024-54661CRITICALCVSS 9.8EG 9.82024-12-04
readline.sh in socat before1.8.0.2 relies on the /tmp/$USER/stderr2 file.
- CVE-2026-55447CRITICALCVSS 9.6EG 9.62026-06-19
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling a files that are digested into the RAG, an attacker can direct the node to read any file on the file-system by absolute path. All…
- CVE-2025-68937CRITICALCVSS 9.5EG 9.52025-12-26
Forgejo before 13.0.2 allows attackers to write to unintended files, and possibly obtain server shell access, because of mishandling of out-of-repository symlink destinations for template repositories. This is also fixed for 11 LTS in 11.0…
- CVE-2026-52811CRITICALCVSS 9.0EG 9.02026-06-23
Gogs is an open source self-hosted Git service. Prior to 0.14.3, (*Repository).UploadRepoFiles checks for symlinks only on the leaf of the upload target (osx.IsSymlink(targetPath)). The siblings UpdateRepoFile, DeleteRepoFile, and GetDiffP…
- CVE-2026-56748HIGHCVSS 8.8EG 8.82026-07-27
Improper validation of symbolic links in the Pack Git import feature in Cribl Stream before 4.18.2 allows a remote authenticated attacker with Pack import and pipeline preview permissions to execute arbitrary code as the Cribl server proce…
- CVE-2026-6475HIGHCVSS 8.8EG 8.82026-05-14
Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starti…
- CVE-2026-29203HIGHCVSS 8.8EG 8.82026-05-08
A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on arbitrary system files or directories. That can cause DoS or local privilege escalation when an authenticated cPanel us…
- CVE-2026-27976HIGHCVSS 8.8EG 8.82026-02-26
Zed, a code editor, has an extension installer allows tar/gzip downloads. Prior to version 0.224.4, the tar extractor (`async_tar::Archive::unpack`) creates symlinks from the archive without validation, and the path guard (`writeable_path_…
- CVE-2025-55345HIGHCVSS 8.8EG 8.82025-08-13
Using Codex CLI in workspace-write mode inside a malicious context (repo, directory, etc) could lead to arbitrary file overwrite and potentially remote code execution due to symlinks being followed outside the allowed current working direc…
- CVE-2024-44132HIGHCVSS 8.8EG 8.82024-09-17
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15. An app may be able to break out of its sandbox.
- CVE-2024-22014HIGHCVSS 8.8EG 8.82024-04-15
An issue discovered in 360 Total Security Antivirus through 11.0.0.1061 for Windows allows attackers to gain escalated privileges via Symbolic Link Follow to Arbitrary File Delete.
- CVE-2026-42275HIGHCVSS 8.7EG 8.72026-05-08
zrok is software for sharing web services, files, and network resources. Prior to version 2.0.2, the zrok WebDAV drive backend (davServer.Dir) restricts path traversal through lexical normalization but does not prevent symlink following. W…
- CVE-2025-59343HIGHCVSS 8.7EG 8.72025-09-24
tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.1.1, 2.1.3, and 1.16.5 are vulnerable to symlink validation bypass if the destination directory is predictable with a specific tarball. This issue has been patched in …
- CVE-2025-57802HIGHCVSS 8.7EG 8.72025-08-25
Airlink's Daemon interfaces with Docker and the Panel to provide secure access for controlling instances via the Panel. In version 1.0.0, an attacker with access to the affected container can create symbolic links inside the mounted direct…
- CVE-2025-67487HIGHCVSS 8.6EG 8.62025-12-09
Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Versions 2.40.0 and below contain symbolic links (symlinks) which can be used to access files or directories outside the intended web root fo…
- CVE-2025-46810HIGHCVSS 8.5EG 8.52025-09-02
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of openSUSE Tumbleweed traefik2 allows the traefik user to escalate to root. This issue affects Tumbleweed: from ? before 2.11.29.
- CVE-2026-39860HIGHCVSS 8.4EG 8.42026-04-08
Nix is a package manager for Linux and other Unix systems. A bug in the fix for CVE-2024-27297 allowed for arbitrary overwrites of files writable by the Nix process orchestrating the builds (typically the Nix daemon running as root in mult…
- CVE-2025-33225HIGHCVSS 8.4EG 8.42025-12-16
NVIDIA Resiliency Extension for Linux contains a vulnerability in log aggregation, where an attacker could cause predictable log-file names. A successful exploit of this vulnerability may lead to escalation of privileges, code execution, d…
- CVE-2026-49248HIGHCVSS 8.3EG 8.32026-06-18
OneDev is a Git server with CI/CD, kanban, and packages. In versions 15.0.6 and below, TarUtils.untar() creates symbolic links verbatim from TAR entry getLinkName() without validating whether the target is an absolute path. A subsequent fi…
- CVE-2026-54574HIGHCVSS 8.2EG 8.22026-07-29
proot-distro is a utility for managing proot containers. Prior to version 5.1.5, proot-distro install extracted plain tarball root filesystems through _extract_plain_tar() in proot_distro/commands/install.py and Docker layers through _appl…
- CVE-2026-41326HIGHCVSS 8.2EG 8.22026-04-24
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. From v3.4.0 to v3.28.0, an oversight in the CopyFile policy (and perhaps the CopyFile handl…
- CVE-2021-39135HIGHCVSS 8.2EG 8.22021-08-31
`@npmcli/arborist`, the library that calculates dependency trees and manages the node_modules folder hierarchy for the npm command line interface, aims to guarantee that package dependency contracts will be met, and the extraction of packa…
- CVE-2021-39134HIGHCVSS 8.2EG 8.22021-08-31
`@npmcli/arborist`, the library that calculates dependency trees and manages the `node_modules` folder hierarchy for the npm command line interface, aims to guarantee that package dependency contracts will be met, and the extraction of pac…
- CVE-2026-107810HIGHCVSS 8.1EG 8.12026-10-09
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, internal/backup/restore.go extracts inner archives before applying the restore_nginx and restore_nginx_ui flags and permits symlinks targeting the live Ngin…
- CVE-2026-56876HIGHCVSS 8.1EG 8.12026-06-26
extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/passwd', extract-zip will extract the symlink without validati…
- CVE-2026-7819HIGHCVSS 8.1EG 8.12026-05-11
Symbolic-link path traversal (CWE-61, CWE-22) in pgAdmin 4 File Manager. check_access_permission used os.path.abspath, which resolves '..' but does not resolve symbolic links, while the subsequent kernel write follows symlinks. An authent…
- CVE-2025-10854HIGHCVSS 8.1EG 8.12025-09-22
The txtai framework allows the loading of compressed tar files as embedding indices. While the validate function is intended to prevent path traversal vulnerabilities by ensuring safe filenames, it does not account for symbolic links withi…
- CVE-2024-47515HIGHCVSS 8.1EG 8.12024-12-24
A vulnerability was found in Pagure. Support of symbolic links during repository archiving of repositories allows the disclosure of local files. This flaw allows a malicious user to take advantage of the Pagure instance.
- CVE-2023-37460HIGHCVSS 8.1EG 8.12023-07-25
Plexis Archiver is a collection of Plexus components to create archives or extract archives to a directory with a unified `Archiver`/`UnArchiver` API. Prior to version 4.8.0, using AbstractUnArchiver for extracting an archive might lead to…
- CVE-2026-79939HIGHCVSS 7.8EG 7.82026-08-26
Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Script injectio…
- CVE-2026-39822HIGHCVSS 7.8EG 7.82026-07-08
On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will ope…
- CVE-2026-12958HIGHCVSS 7.8EG 7.82026-06-23
Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary. This may occur when a local user opens a workspace with a maliciously crafted symlink that resolves to a file…
- CVE-2026-33711HIGHCVSS 7.8EG 7.82026-03-26
Incus is a system container and virtual machine manager. Incus provides an API to retrieve VM screenshots. That API relies on the use of a temporary file for QEMU to write the screenshot to which is then picked up and sent to the user prio…
- CVE-2026-24018HIGHCVSS 7.8EG 7.82026-03-10
A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinux 7.2.2 through 7.2.12 may allow a local and unprivileged user to escalate their privileges to root.
- CVE-2025-66431HIGHCVSS 7.8EG 7.82025-12-03
WebPros Plesk before 18.0.73.5 and 18.0.74 before 18.0.74.2 on Linux allows remote authenticated users to execute arbitrary code as root via domain creation. The attacker needs "Create and manage sites" with "Domains management" and "Subdo…
- CVE-2025-31133HIGHCVSS 7.8EG 7.82025-11-06
runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, 1.3.0-rc.1 through 1.3.1, 1.4.0-rc.1 and 1.4.0-rc.2 files, runc would not perform sufficient verification that the sour…
- CVE-2025-36564HIGHCVSS 7.8EG 7.82025-06-03
Dell Encryption Admin Utilities versions prior to 11.10.2 contain an Improper Link Resolution vulnerability. A local malicious user could potentially exploit this vulnerability, leading to privilege escalation.
- CVE-2025-1079HIGHCVSS 7.8EG 7.82025-05-12
Client RCE on macOS and Linux via improper symbolic link resolution in Google Web Designer's preview feature
- CVE-2024-47480HIGHCVSS 7.8EG 7.82024-12-18
Dell Inventory Collector Client, versions prior to 12.7.0, contains an Improper Link Resolution Before File Access vulnerability. A low-privilege attacker with local access may exploit this vulnerability, potentially resulting in Elevation…
Map vulnerabilities like CWE-61 to your infrastructure
EchelonGraph correlates every CVE — across CWE-61 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →