VYPR

CWE-59

Improper Link Resolution Before File Access ('Link Following')

BaseDraftLikelihood: Medium

Description

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76

CVEs mapped to this weakness (1,658)

page 33 of 83
  • CVE-2021-32610HigJul 30, 2021
    risk 0.45cvss 7.1epss 0.73

    In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.

  • CVE-2026-65680MedAug 11, 2026
    risk 0.44cvss 6.7epss 0.00

    Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.

  • CVE-2026-63622HigAug 10, 2026
    risk 0.44cvss 7.8epss 0.00

    A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within the `swtpm` state directory, the attacker could…

  • CVE-2026-11940HigJun 23, 2026
    risk 0.44cvss epss 0.01

    tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself.  The extraction fallback validated the symlink at it's archived location but recreated it at…

  • CVE-2026-44711HigMay 27, 2026
    risk 0.44cvss 7.9epss 0.00

    pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, symlink attacks on pad directory and pad files enable authentication bypass and root file corruption. This vulnerability is fixed in 0.8.7.

  • CVE-2026-2808MedMar 12, 2026
    risk 0.44cvss 6.8epss 0.00

    HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.

  • CVE-2026-27905HigMar 3, 2026
    risk 0.44cvss 7.8epss 0.00

    BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.36, the safe_extract_tarfile() function validates that each tar member's path is within the destination directory, but for symlink members it only validates…

  • CVE-2025-67124MedJan 23, 2026
    risk 0.44cvss 6.8epss 0.00

    A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the…

  • CVE-2025-24918MedNov 11, 2025
    risk 0.44cvss 6.7epss 0.00

    Improper link resolution before file access ('link following') for some Intel(R) Server Configuration Utility software and Intel(R) Server Firmware Update Utility software before version 16.0.12. within Ring 3: User Applications may allow an escalation of privilege. System…

  • CVE-2025-5718MedNov 11, 2025
    risk 0.44cvss 6.8epss 0.00

    The ACAP Application framework could allow privilege escalation through a symlink attack. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a…

  • CVE-2025-43726MedSep 2, 2025
    risk 0.44cvss 6.7epss 0.00

    Dell Alienware Command Center 5.x (AWCC), versions prior to 5.10.2.0, contains an Improper Link Resolution Before File Access ('Link Following')" vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of…

  • CVE-2025-29983MedApr 15, 2025
    risk 0.44cvss 6.7epss 0.00

    Dell Trusted Device, versions prior to 7.0.3.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

  • CVE-2023-43078MedAug 28, 2024
    risk 0.44cvss 6.7epss 0.00

    Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege Escalation or Denial of Service.

  • CVE-2024-38013MedJul 9, 2024
    risk 0.44cvss 6.7epss 0.01

    Microsoft Windows Server Backup Elevation of Privilege Vulnerability

  • CVE-2024-5742MedJun 12, 2024
    risk 0.44cvss 6.7epss 0.00

    A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to…

  • CVE-2024-30076MedJun 11, 2024
    risk 0.44cvss 6.8epss 0.02

    Windows Container Manager Service Elevation of Privilege Vulnerability

  • CVE-2024-31952MedMay 14, 2024
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in Samsung Magician 8.0.0 on macOS. Because symlinks are used during the installation process, an attacker can escalate privileges via arbitrary file permission writes. (The attacker must already have user privileges, and an administrator password must be…

  • CVE-2024-29188HigMar 24, 2024
    risk 0.44cvss 7.9epss 0.00

    WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. The custom action behind WiX's `RemoveFolderEx` functionality could allow a standard user to delete protected directories. `RemoveFolderEx` deletes an entire directory tree…

  • CVE-2023-43116HigDec 22, 2023
    risk 0.44cvss 7.8epss 0.00

    A symbolic link following vulnerability in Buildkite Elastic CI for AWS versions prior to 6.7.1 and 5.22.5 allows the buildkite-agent user to change ownership of arbitrary directories via the PIPELINE_PATH variable in the fix-buildkite-agent-builds-permissions script.

  • CVE-2023-28065MedJun 23, 2023
    risk 0.44cvss 6.7epss 0.00

    Dell Command | Update, Dell Update, and Alienware Update versions 4.8.0 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability leading to privilege escalation.