CWE-59— Improper Link Resolution Before File Access (Link Following)
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.— MITRE CWE catalog
1,705 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-59page 34 of 35
- CVE-2026-70622MEDIUMCVSS 6.5EG 6.52026-08-10
tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function that allows attackers to read files outside the intended source root directory by planting symlinks in an attacker-contr…
- CVE-2026-70626MEDIUMCVSS 6.2EG 6.22026-08-22
NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to read arbitrary files outside the corpus root. The vulnerability exists because path validation is lexical and does not …
- CVE-2026-71181LOWCVSS 3.0EG 3.02026-09-16
Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability,…
- CVE-2026-71182LOWCVSS 3.0EG 3.02026-09-16
Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability,…
- CVE-2026-71476HIGHCVSS 8.7EG 8.72026-08-06
Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx self-hosted HTTP remote cache extracts downloaded cache artifacts without constraining where files are written. A maliciou…
- CVE-2026-71493MEDIUMCVSS 5.9EG 5.92026-08-21
Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, the readFile, pathExists, isDir, and matchPaths template functions in internal/config/template/parser.go use a lexical filepath.Rel ch…
- CVE-2026-71556HIGHCVSS 7.1EG 7.12026-08-07
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution…
- CVE-2026-71964MEDIUMCVSS 6.5EG 6.52026-08-10
CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file manager component that allows authenticated attackers to read sensitive system files by uploading a crafted ZIP archive containing symboli…
- CVE-2026-72694HIGHCVSS 7.1EG 7.12026-08-11
A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can exploit a symbolic link (symlink) following vulnerability. By influencing or pre-placing a sym…
- CVE-2026-72696HIGHCVSS 8.4EG 8.42026-08-25
Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job::createLockFile() that allows local attackers to overwrite arbitrary files by pre-creating symlinks at predictable lock file paths in the world-writable tem…
- CVE-2026-72971MEDIUMCVSS 5.5EG 5.52026-08-11
Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.
- CVE-2026-73613HIGHCVSS 8.2EG 8.22026-08-13
filebrowser versions before 2.63.19 contain an out-of-scope file deletion vulnerability in the TUS upload cache eviction mechanism that allows authenticated users with only Create permission to delete arbitrary files outside their scope. A…
- CVE-2026-7374CRITICALCVSS 9.9EG 9.92026-05-26
A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console …
- CVE-2026-7397MEDIUMCVSS 4.4EG 4.42026-04-29
A security flaw has been discovered in NousResearch hermes-agent 0.8.0. This affects the function _check_sensitive_path of the file tools/file_tools.py. The manipulation results in symlink following. Attacking locally is a requirement. The…
- CVE-2026-74796MEDIUMCVSS 6.1EG 6.12026-08-16
OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious symlink in a trusted working directory to cause tofu init to write provider package contents …
- CVE-2026-76037HIGHCVSS 8.4EG 8.42026-08-18
Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
- CVE-2026-76845MEDIUMCVSS 6.5EG 6.52026-08-24
adm-zip 0.5.9 through 0.6.0 follows symbolic links at the extraction destination. Utils.sanitize in util/utils.js enforces containment by comparing only the string form of an archive entry name against the resolved extraction root, and Uti…
- CVE-2026-77179CRITICALCVSS 9.4EG 9.42026-09-15
On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and …
- CVE-2026-77815HIGHCVSS 7.5EG 7.52026-08-21
to_abs_path in scripts/iib/tool.py normalised the requested path with os.path.normpath, which collapses dot segments but does not resolve symbolic links. A symlink placed inside a scanned directory therefore satisfies the containment compa…
- CVE-2026-7832HIGHCVSS 7.0EG 7.02026-05-05
A security flaw has been discovered in IObit Advanced SystemCare 19. This affects an unknown part of the file ASC.exe of the component Service. The manipulation results in symlink following. Attacking locally is a requirement. This attack …
- CVE-2026-78409HIGHCVSS 7.0EG 7.02026-09-02
The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution insi…
- CVE-2026-78622MEDIUMCVSS 6.0EG 6.02026-09-08
The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges. The delete operation follows the junction target, resulting in recursiv…
- CVE-2026-79655HIGHCVSS 7.8EG 7.82026-08-25
A flaw was found in sos clean, a utility within the sos package. This vulnerability allows a local attacker to perform arbitrary file creation or overwrite. By crafting a malicious tar archive, an attacker can exploit a path traversal issu…
- CVE-2026-79699MEDIUMCVSS 4.4EG 4.42026-09-15
A flaw was found in the containers/storage library. A crafted tar archive containing a malicious whiteout header (e.g. victim/.wh.) can cause the extraction destination directory to be replaced with an arbitrary file when processed by stor…
- CVE-2026-8052MEDIUMCVSS 6.0EG 6.02026-05-12
HashiCorp Nomad’s exec2 task driver prior to 0.1.2 is vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-8052) is fixed in version 0.1.2 of the …
- CVE-2026-81572HIGHCVSS 7.8EG 7.82026-08-27
In CodeMeter Runtime from version 8.40 to (excluding) 8.41a and 9.00 to (excluding) 9.10, cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and file paths are not properly checked for NTFS …
- CVE-2026-81690HIGHCVSS 7.3EG 7.32026-08-27
openssl-encrypt (pip package) before 1.4.9 contains a symlink-following flaw in its verify-usb v2 added-file allowlist scan. The scan enumerated the drive with rglob(), which in CPython does not descend into symlinked directories and treat…
- CVE-2026-8170HIGHCVSS 8.7EG 8.72026-07-20
The mv, cp, and rm file utilities exposed within the ExtremeXOS (EXOS) shell environment fail to safely canonicalize paths and follow symbolic links outside of the intended privilege boundary. An attacker with low-privilege CLI access can …
- CVE-2026-81726HIGHCVSS 7.0EG 7.02026-08-27
NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. Attackers can read or write files outside allowed sandbox roots thr…
- CVE-2026-81727HIGHCVSS 7.1EG 7.12026-08-27
NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardli…
- CVE-2026-81963CRITICALCVSS 7.8EG 9.0⚠ KEV2026-09-08
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
- CVE-2026-82049HIGHCVSS 8.4EG 8.42026-09-14
In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification …
- CVE-2026-82248MEDIUMCVSS 5.3EG 5.32026-08-28
gix-worktree-state before 0.33.0 (part of gitoxide) allows writing files outside the worktree on Windows. gix_worktree_state::checkout() follows an existing terminal symlink during non-exclusive (incremental) materialization (destination_i…
- CVE-2026-82252HIGHCVSS 7.5EG 7.52026-08-28
gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repository bytes into submodule metadata. Attackers can create a malicious repository with a symlinked .gitmodules poin…
- CVE-2026-83999HIGHCVSS 7.0EG 7.02026-09-08
Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-84584HIGHCVSS 8.4EG 8.42026-09-14
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Golden Gate 27. An app may be able to break out of its sandbox.
- CVE-2026-85092MEDIUMCVSS 6.6EG 6.62026-09-03
LiME through 1.12.0 fails to validate the disk acquisition output path and does not use O_NOFOLLOW when opening the operator-supplied path parameter, allowing unprivileged local users to overwrite arbitrary root-owned files. An attacker wh…
- CVE-2026-85583MEDIUMCVSS 6.5EG 6.52026-09-04
SiYuan versions before v3.8.2 contain a path traversal vulnerability in the reader-accessible file-read endpoint that follows symlinks when opening authorized asset paths. Attackers with reader role can request a logical asset under data/a…
- CVE-2026-85731HIGHCVSS 8.8EG 8.82026-09-16
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, content/file.Store extraction of OCI layers marked with io.deis.oras.content.unpack=true can write outside the store working directory. The pushDir path through extractTar…
- CVE-2026-86422LOWCVSS 3.3EG 3.32026-09-07
ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restrictions by exploiting symlink race conditions. Attackers can swap symli…
- CVE-2026-86424LOWCVSS 2.5EG 2.52026-09-07
ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink swaps. An attacker can replace a symlink …
- CVE-2026-86469MEDIUMCVSS 5.3EG 5.32026-09-07
A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or…
- CVE-2026-86861MEDIUMCVSS 5.9EG 5.92026-09-17
pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested path with Filemanager.check_access_permission() and then opened the file for writing with a plain open() call. CVE-2026-78…
- CVE-2026-87766HIGHCVSS 8.8EG 8.82026-09-09
A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching user. This ha…
- CVE-2026-8784MEDIUMCVSS 4.2EG 4.22026-05-18
A vulnerability was detected in npitre cramfs-tools up to 2.2. Affected is the function change_file_status of the file cramfsck.c. Performing a manipulation results in symlink following. The attack requires a local approach. The exploit is…
- CVE-2026-87910MEDIUMCVSS 5.7EG 5.72026-09-11
When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the locati…
- CVE-2026-88016HIGHCVSS 7.1EG 7.12026-09-10
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, when backend/local runs with --links, a source .rclonelink object can plant a symlink in the destination and lat…
- CVE-2026-88264MEDIUMCVSS 5.6EG 5.62026-09-10
A flaw was found in crun. When the container configuration does not give /dev a dedicated mount, terminal setup can redirect /dev/console onto an attacker-controlled path, including via the read-only-rootfs bind-mount fallback. Affected ve…
- CVE-2026-88265MEDIUMCVSS 5.6EG 5.62026-09-10
A flaw was found in crun. After pivot_root, reopening /dev/null for stdio can follow a symlink and attach a host file to container stdio, then change that file's ownership. Affected versions are crun 1.29.1 and earlier. Default configurati…
- CVE-2026-89021MEDIUMCVSS 6.9EG 6.92026-09-14
MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container root by supplying a crafted container image with symlinks …
Map vulnerabilities like CWE-59 to your infrastructure
EchelonGraph correlates every CVE — across CWE-59 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →