VYPR

CWE-59

Improper Link Resolution Before File Access ('Link Following')

BaseDraftLikelihood: Medium

Description

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76

CVEs mapped to this weakness (1,658)

page 4 of 83
  • CVE-2025-47181HigMay 22, 2025
    risk 0.57cvss 8.8epss 0.01

    Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.

  • CVE-2024-12390HigMar 20, 2025
    risk 0.57cvss 8.8epss 0.02

    A vulnerability in binary-husky/gpt_academic version git 310122f allows for remote code execution. The application supports the extraction of user-provided RAR files without proper validation. The Python rarfile module, which supports symlinks, can be exploited to perform…

  • CVE-2024-10986HigMar 20, 2025
    risk 0.57cvss 8.8epss 0.01

    GPT Academic version 3.83 is vulnerable to a Local File Read (LFI) vulnerability through its HotReload function. This function can download and extract tar.gz files from arxiv.org. Despite implementing protections against path traversal, the application overlooks the Tarslip…

  • CVE-2024-50404HigDec 6, 2024
    risk 0.57cvss 8.8epss 0.01

    A link following vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations. We have already fixed the vulnerability in the following…

  • CVE-2024-27458HigOct 7, 2024
    risk 0.57cvss 8.8epss 0.00

    A potential security vulnerability has been identified in the HP Hotkey Support software, which might allow local escalation of privilege. HP is releasing mitigation for the potential vulnerability. Customers using HP Programmable Key are recommended to update HP Hotkey Support.

  • CVE-2024-44132HigSep 17, 2024
    risk 0.57cvss 8.8epss 0.00

    This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15. An app may be able to break out of its sandbox.

  • CVE-2024-28916HigMar 21, 2024
    risk 0.57cvss 8.8epss 0.01

    Xbox Gaming Services Elevation of Privilege Vulnerability

  • CVE-2023-28872HigDec 25, 2023
    risk 0.57cvss 8.8epss 0.01

    Support Assistant in NCP Secure Enterprise Client before 13.10 allows attackers to execute DLL files with SYSTEM privileges by creating a symbolic link from a %LOCALAPPDATA%\Temp\NcpSupport* location.

  • CVE-2023-6069CriNov 10, 2023
    risk 0.57cvss 9.9epss 0.01

    Improper Link Resolution Before File Access in GitHub repository froxlor/froxlor prior to 2.1.0.

  • CVE-2023-4759HigSep 12, 2023
    risk 0.57cvss 8.8epss 0.02

    Arbitrary File Overwrite in Eclipse JGit <= 6.6.0 In Eclipse JGit, all versions <= 6.6.0.202305301015-r, a symbolic link present in a specially crafted git repository can be used to write a file to locations outside the working tree when this repository is cloned with JGit to a…

  • CVE-2023-33245HigMay 30, 2023
    risk 0.57cvss 8.8epss 0.01

    Minecraft through 1.19 and 1.20 pre-releases before 7 (Java) allow arbitrary file overwrite, and possibly code execution, via crafted world data that contains a symlink.

  • CVE-2022-45412HigDec 22, 2022
    risk 0.57cvss 8.8epss 0.01

    When resolving a symlink such as file:///proc/self/fd/1, an error message may be produced where the symlink was resolved to a string containing unitialized memory in the buffer. *This bug only affects Thunderbird on Unix-based operated systems (Android, Linux,…

  • CVE-2022-26612CriApr 7, 2022
    risk 0.57cvss 9.8epss 0.04

    In Apache Hadoop, The unTar function uses unTarUsingJava function on Windows and the built-in tar utility on Unix and other OSes. As a result, a TAR entry may create a symlink under the expected extraction directory which points to an external directory. A subsequent TAR entry…

  • CVE-2022-0799HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Insufficient policy enforcement in Installer in Google Chrome on Windows prior to 99.0.4844.51 allowed a remote attacker to perform local privilege escalation via a crafted offline installer file.

  • CVE-2021-21691CriNov 4, 2021
    risk 0.57cvss 9.8epss 0.02

    Creating symbolic links is possible without the 'symlink' agent-to-controller access control permission in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.

  • CVE-2020-7319HigSep 9, 2020
    risk 0.57cvss 8.8epss 0.00

    Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local users to access files which the user otherwise would not have access to via manipulating symbolic links to redirect McAfee file operations to an…

  • CVE-2020-15932HigJul 24, 2020
    risk 0.57cvss 8.8epss 0.03

    Overwolf before 0.149.2.30 mishandles Symbolic Links during updates, causing elevation of privileges.

  • CVE-2020-13095HigJun 30, 2020
    risk 0.57cvss 8.8epss 0.02

    Little Snitch version 4.5.1 and older changed ownership of a directory path controlled by the user. This allowed the user to escalate to root by linking the path to a directory containing code executed by root.

  • CVE-2020-12265CriApr 26, 2020
    risk 0.57cvss 9.8epss 0.02

    The decompress package before 4.2.1 for Node.js is vulnerable to Arbitrary File Write via ../ in an archive member, when a symlink is used, because of Directory Traversal.

  • CVE-2020-10947HigApr 17, 2020
    risk 0.57cvss 8.8epss 0.02

    Mac Endpoint for Sophos Central before 9.9.6 and Mac Endpoint for Sophos Home before 2.2.6 allow Privilege Escalation.