CWE-59— Improper Link Resolution Before File Access (Link Following)
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.— MITRE CWE catalog
1,705 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-59page 29 of 35
- CVE-2026-15684HIGHCVSS 7.3EG 7.32026-07-13
Glarysoft Glary Utilities Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Glarysoft Glary Utilities. An attacker must first obtain the a…
- CVE-2026-15788HIGHCVSS 7.5EG 7.52026-07-20
BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cache root. A build authored by an untrusted user on a WCOW-configured BuildKit daemon can re…
- CVE-2026-15815HIGHCVSS 8.8EG 8.82026-09-17
Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin installation directory, writing arbitrary file…
- CVE-2026-15994HIGHCVSS 7.0EG 7.02026-08-13
During an internal security assessment, an improper link following vulnerability was identified in Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to execute code with elevated privileges.
- CVE-2026-16077MEDIUMCVSS 5.3EG 5.32026-07-18
A vulnerability was found in AstrBotDevs AstrBot up to 4.25.5. Impacted is the function _normalize_rw_path of the file astrbot/core/tools/computer_tools/fs.py of the component Filesystem Computer-Use Tool. Performing a manipulation results…
- CVE-2026-16130MEDIUMCVSS 4.4EG 4.42026-07-18
A vulnerability was identified in nearai ironclaw up to 0.29.1. The affected element is the function validate_path of the file src/tools/builtin/path_utils.rs of the component write_file. The manipulation leads to link following. Local acc…
- CVE-2026-16980MEDIUMCVSS 5.5EG 6.32026-08-20
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to improper validation of symbolic links.
- CVE-2026-16989HIGHCVSS 7.8EG 7.82026-08-20
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper resolution of symbolic links.
- CVE-2026-17106HIGHCVSS 7.1EG 7.12026-08-18
The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extractor decides where each archive entry lan…
- CVE-2026-17171HIGHCVSS 7.8EG 7.82026-08-20
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite arbitrary files due to improper resolution of symbolic links.
- CVE-2026-17435LOWCVSS 2.5EG 2.52026-08-07
File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files. When the file to be rotated is a symbolic link to a missing file, and the touch option is enabled, then the rotate method assu…
- CVE-2026-17459MEDIUMCVSS 4.3EG 4.32026-07-26
A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.externalLocation of the file src/main/java/spark/resource/ExternalResourceHandler.jav of the component SparkJava. Executing …
- CVE-2026-18267MEDIUMCVSS 6.8EG 6.82026-08-20
Kenwood DNR1007XR Firmware Update Link Following Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DNR1007XR devices. Authentication is not r…
- CVE-2026-18508MEDIUMCVSS 4.4EG 4.42026-08-03
A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archiv…
- CVE-2026-19008MEDIUMCVSS 6.3EG 6.32026-08-06
A vulnerability was identified in mf-yang openclaw-cn up to 0.2.1. This issue affects the function assertNoSymlinkEscape of the file src/agents/sandbox-paths.ts of the component apply_patch Tool. Such manipulation leads to link following. …
- CVE-2026-19693HIGHCVSS 8.1EG 8.12026-08-17
extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the …
- CVE-2026-19820HIGHCVSS 7.8EG 7.82026-09-01
A vulnerability in the Backblaze Client allows a local user to make the system not bootable by creating a link from Backblaze's folder to Windows OS system files during a backup. Successful exploitation requires an administrator-level syst…
- CVE-2026-19909HIGHCVSS 7.5EG 7.52026-08-14
PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not r…
- CVE-2026-20161MEDIUMCVSS 5.5EG 5.52026-04-15
A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent could allow an authenticated, local attacker with low privileges to overwrite arbitrary files on the local system of an affected device. This vulnerability is due to impr…
- CVE-2026-20310CRITICALCVSS 9.1EG 9.12026-08-05
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that ad…
- CVE-2026-20610HIGHCVSS 7.8EG 7.82026-02-11
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Tahoe 26.3. An app may be able to gain root privileges.
- CVE-2026-20633MEDIUMCVSS 5.5EG 5.52026-03-25
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access user-sensitive data.
- CVE-2026-20694MEDIUMCVSS 5.5EG 5.52026-03-25
This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.4, macOS Sonoma 14.8.5, macOS Tahoe 26.3, macOS Tahoe 26.4. An app …
- CVE-2026-20941HIGHCVSS 7.8EG 7.82026-01-13
Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.
- CVE-2026-21419MEDIUMCVSS 6.6EG 6.62026-02-09
Dell Display and Peripheral Manager (Windows) versions prior to 2.2 contain an Improper Link Resolution Before File Access ('Link Following') vulnerability in the Installer and Service. A low privileged attacker with local access could pot…
- CVE-2026-21517HIGHCVSS 7.0EG 7.02026-02-10
Improper link resolution before file access ('link following') in Windows App for Mac allows an authorized attacker to elevate privileges locally.
- CVE-2026-22180MEDIUMCVSS 5.3EG 5.32026-03-18
OpenClaw versions prior to 2026.3.2 contain a path-confinement bypass vulnerability in browser output handling that allows writes outside intended root directories. Attackers can exploit insufficient canonical path-boundary validation in f…
- CVE-2026-22701MEDIUMCVSS 5.3EG 5.32026-01-10
filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker with local filesystem access and permiss…
- CVE-2026-22702MEDIUMCVSS 4.5EG 4.52026-01-10
virtualenv is a tool for creating isolated virtual python environments. Prior to version 20.36.1, TOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in virtualenv allow local attackers to perform symlink-based attacks on directory creation…
- CVE-2026-23563HIGHCVSS 7.1EG 7.12026-01-29
Improper Link Resolution Before File Access (invoked by 1E‑Explorer‑TachyonCore‑DeleteFileByPath instruction) in TeamViewer DEX - 1E Client before version 26.1 on Windows allows a low‑privileged local attacker to delete protected s…
- CVE-2026-23879HIGHCVSS 8.0EG 8.02026-06-19
py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Versions 1.1.2 and below contain an an arbitrary file write vulnerability, which allows symbolic links to be recreat…
- CVE-2026-23893MEDIUMCVSS 6.8EG 6.82026-01-22
openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. Versions 2.3.2 and above are vulnerable to symlink-following when running in privileged contexts. A token-group user can redirect file operations to arbitrary filesy…
- CVE-2026-24046HIGHCVSS 7.1EG 7.12026-01-21
Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder t…
- CVE-2026-24047MEDIUMCVSS 6.3EG 6.32026-01-21
Backstage is an open framework for building developer portals, and @backstage/cli-common provides config loading functionality used by the backend and command line interface of Backstage. Prior to version 0.1.17, the `resolveSafeChildPath`…
- CVE-2026-24056MEDIUMCVSS 6.5EG 6.52026-01-26
pnpm is a package manager. Prior to version 10.28.2, when pnpm installs a `file:` (directory) or `git:` dependency, it follows symlinks and reads their target contents without constraining them to the package root. A malicious package cont…
- CVE-2026-24842HIGHCVSS 8.2EG 8.22026-01-28
node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacke…
- CVE-2026-24884HIGHCVSS 7.8EG 7.82026-02-04
Compressing is a compressing and uncompressing lib for node. In version 2.0.0 and 1.10.3 and prior, Compressing extracts TAR archives while restoring symbolic links without validating their targets. By embedding symlinks that resolve outsi…
- CVE-2026-2490MEDIUMCVSS 5.5EG 5.52026-02-20
RustDesk Client for Windows Transfer File Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of RustDesk Client for Windows. An attacke…
- CVE-2026-25187HIGHCVSS 7.8EG 7.82026-03-10
Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally.
- CVE-2026-25718CRITICALCVSS 9.1EG 9.12026-07-03
Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processing to read or write through symlinked or otherwise non-regular paths.
- CVE-2026-25906HIGHCVSS 7.8EG 7.82026-03-03
Dell Optimizer, versions prior to 6.3.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevatio…
- CVE-2026-26225HIGHCVSS 8.5EG 8.52026-02-12
Intego Personal Backup, a macOS backup utility that allows users to create scheduled backups and bootable system clones, contains a local privilege escalation vulnerability. Backup task definitions are stored in a location writable by non-…
- CVE-2026-2627HIGHCVSS 7.8EG 7.82026-02-17
A security flaw has been discovered in Softland FBackup up to 9.9. This impacts an unknown function in the library C:\Program Files\Common Files\microsoft shared\ink\HID.dll of the component Backup/Restore. The manipulation results in link…
- CVE-2026-27105MEDIUMCVSS 6.3EG 6.32026-04-29
Dell/Alienware Purchased Apps, versions prior to 1.1.31.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, l…
- CVE-2026-27456MEDIUMCVSS 4.7EG 4.72026-04-03
util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop…
- CVE-2026-27748HIGHCVSS 7.1EG 7.82026-03-05
Avira Internet Security contains an improper link resolution vulnerability in the Software Updater component. During the update process, a privileged service running as SYSTEM deletes a file under C:\\ProgramData without validating whether…
- CVE-2026-27905HIGHCVSS 7.8EG 7.82026-03-03
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.36, the safe_extract_tarfile() function validates that each tar member's path is within the destination directory, but …
- CVE-2026-27967HIGHCVSS 7.1EG 7.12026-02-26
Zed, a code editor, has a symlink escape vulnerability in versions prior to 0.225.9 in Agent file tools (`read_file`, `edit_file`). It allows reading and writing files **outside the project directory** when a project contains symbolic link…
- CVE-2026-2808MEDIUMCVSS 6.8EG 6.82026-03-11
HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.
- CVE-2026-28262MEDIUMCVSS 6.0EG 6.02026-06-09
Dell iDRAC Tools, versions prior to 11.4.1.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to In…
Map vulnerabilities like CWE-59 to your infrastructure
EchelonGraph correlates every CVE — across CWE-59 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →