VYPR

CWE-59

Improper Link Resolution Before File Access ('Link Following')

BaseDraftLikelihood: Medium

Description

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76

CVEs mapped to this weakness (1,754)

page 26 of 88
  • CVE-2026-82049HigSep 14, 2026
    risk 0.48cvss —epss 0.00

    In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination…

  • CVE-2026-55108HigAug 28, 2026
    risk 0.48cvss 8.5epss 0.01

    KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until 1.10.9, and from 1.11.0-alpha.1 until 1.11.0-alpha.4, the Terraform remote configuration loader in pkg/controller/utils/capability.go, GetTerraformConfigurationFromRemote, clones…

  • CVE-2026-72696HigAug 25, 2026
    risk 0.48cvss 8.4epss 0.00

    Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job::createLockFile() that allows local attackers to overwrite arbitrary files by pre-creating symlinks at predictable lock file paths in the world-writable temp directory. Attackers can place a…

  • CVE-2026-43989HigMay 12, 2026
    risk 0.48cvss 8.5epss 0.00

    JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, the upload_wasm MCP tool accepted a filesystem path from the agent and uploaded whatever bytes the path resolved to, with no validation of location, symlink target, file size, or file format.…

  • CVE-2026-41882HigApr 30, 2026
    risk 0.48cvss 7.4epss 0.00

    In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server

  • CVE-2026-40931HigApr 21, 2026
    risk 0.48cvss 8.4epss 0.00

    Compressing is a compressing and uncompressing lib for node. Prior to 2.1.1 and 1.10.5, the patch for CVE-2026-24884 relies on a purely logical string validation within the isPathWithinParent utility. This check verifies if a resolved path string starts with the destination…

  • CVE-2025-63946HigFeb 23, 2026
    risk 0.48cvss 7.4epss 0.00

    A privilege escalation (PE) vulnerability in the Tencent PC Manager app thru 17.10.28554.205 on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition.

  • CVE-2025-63945HigFeb 23, 2026
    risk 0.48cvss 7.4epss 0.00

    A privilege escalation (PE) vulnerability in the Tencent iOA app thru 210.9.28693.621001 on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition.

  • CVE-2026-24884HigFeb 4, 2026
    risk 0.48cvss 8.4epss 0.00

    Compressing is a compressing and uncompressing lib for node. In version 2.0.0 and 1.10.3 and prior, Compressing extracts TAR archives while restoring symbolic links without validating their targets. By embedding symlinks that resolve outside the intended extraction directory, an…

  • CVE-2025-21331HigJan 14, 2025
    risk 0.48cvss 7.3epss 0.01

    Windows Installer Elevation of Privilege Vulnerability

  • CVE-2024-49107HigDec 12, 2024
    risk 0.48cvss 7.3epss 0.02

    WmsRepair Service Elevation of Privilege Vulnerability

  • CVE-2024-43470HigSep 10, 2024
    risk 0.48cvss 7.3epss 0.01

    Azure Network Watcher VM Agent Elevation of Privilege Vulnerability

  • CVE-2024-38081HigJul 9, 2024
    risk 0.48cvss 7.3epss 0.01

    .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability

  • CVE-2024-30093HigJun 11, 2024
    risk 0.48cvss 7.3epss 0.01

    Windows Storage Elevation of Privilege Vulnerability

  • CVE-2024-26216HigApr 9, 2024
    risk 0.48cvss 7.3epss 0.01

    Windows File Server Resource Management Service Elevation of Privilege Vulnerability

  • CVE-2024-21329HigFeb 13, 2024
    risk 0.48cvss 7.3epss 0.01

    Azure Connected Machine Agent Elevation of Privilege Vulnerability

  • CVE-2023-35624HigDec 12, 2023
    risk 0.48cvss 7.3epss 0.01

    Azure Connected Machine Agent Elevation of Privilege Vulnerability

  • CVE-2023-25152HigFeb 8, 2023
    risk 0.48cvss 8.4epss 0.01

    Wings is Pterodactyl's server control plane. Affected versions are subject to a vulnerability which can be used to create new files and directory structures on the host system that previously did not exist, potentially allowing attackers to change their resource allocations,…

  • CVE-2021-41641HigJun 12, 2022
    risk 0.48cvss 8.4epss 0.00

    Deno <=1.14.0 file sandbox does not handle symbolic links correctly. When running Deno with specific write access, the Deno.symlink method can be used to gain access to any directory.

  • CVE-2022-27883HigApr 9, 2022
    risk 0.48cvss 7.3epss 0.01

    A link following vulnerability in Trend Micro Antivirus for Mac 11.5 could allow an attacker to create a specially-crafted file as a symlink that can lead to privilege escalation. Please note that an attacker must at least have low-level privileges on the system to attempt to…