VYPR

CWE-59

Improper Link Resolution Before File Access ('Link Following')

BaseDraftLikelihood: Medium

Description

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76

CVEs mapped to this weakness (1,658)

page 43 of 83
  • CVE-2026-72971MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.

  • CVE-2026-70348MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.

  • CVE-2026-15059MedAug 10, 2026
    risk 0.36cvss 5.5epss 0.00

    Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation.

  • CVE-2026-58414MedJul 20, 2026
    risk 0.36cvss 5.5epss 0.00

    Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.backup()` recursively collects files using `_collectBackupFiles()`. `_collectBackupFiles()` uses `statSync(full)`, which follows symlinks. If `data/` contains a symlink…

  • CVE-2025-46293MedJun 11, 2026
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.

  • CVE-2026-48693MedMay 26, 2026
    risk 0.36cvss 5.5epss 0.00

    FastNetMon Community Edition through 1.2.9 is vulnerable to a local symlink attack via predictable file paths in /tmp. The statistics file path defaults to '/tmp/fastnetmon.dat' (src/fastnetmon.cpp line 159). The print_screen_contents_into_file() function…

  • CVE-2026-6941MedApr 23, 2026
    risk 0.36cvss 6.6epss 0.00

    radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to read or write files outside the configured project directory by importing a malicious .zrp archive containing a symlinked notes.txt file. Attackers can craft a…

  • CVE-2026-35365MedApr 22, 2026
    risk 0.36cvss 6.6epss 0.00

    The mv utility in uutils coreutils improperly handles directory trees containing symbolic links during moves across filesystem boundaries. Instead of preserving symlinks, the implementation expands them, copying the linked targets as real files or directories at the destination.…

  • CVE-2026-28684MedApr 20, 2026
    risk 0.36cvss 6.6epss 0.00

    python-dotenv reads key-value pairs from a .env file and can set them as environment variables. Prior to version 1.2.2, `set_key()` and `unset_key()` in python-dotenv follow symbolic links when rewriting `.env` files, allowing a local attacker to overwrite arbitrary files via a…

  • CVE-2026-20161MedApr 15, 2026
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent could allow an authenticated, local attacker with low privileges to overwrite arbitrary files on the local system of an affected device. This vulnerability is due to improper access controls on files that are…

  • CVE-2026-32212MedApr 14, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

  • CVE-2026-20694MedMar 25, 2026
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.4, macOS Sonoma 14.8.5, macOS Tahoe 26.3, macOS Tahoe 26.4. An app may be able to access user-sensitive…

  • CVE-2026-20633MedMar 25, 2026
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access user-sensitive data.

  • CVE-2026-2490MedFeb 20, 2026
    risk 0.36cvss 5.5epss 0.00

    RustDesk Client for Windows Transfer File Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of RustDesk Client for Windows. An attacker must first obtain the ability to…

  • CVE-2025-15314MedFeb 10, 2026
    risk 0.36cvss 5.5epss 0.00

    Tanium addressed an arbitrary file deletion vulnerability in end-user-cx.

  • CVE-2025-15313MedFeb 10, 2026
    risk 0.36cvss 5.5epss 0.00

    Tanium addressed an arbitrary file deletion vulnerability in Tanium EUSS.

  • CVE-2025-15318MedFeb 9, 2026
    risk 0.36cvss 5.5epss 0.00

    Tanium addressed an arbitrary file deletion vulnerability in End-User Notifications Endpoint Tools.

  • CVE-2025-13154MedJan 14, 2026
    risk 0.36cvss 5.5epss 0.00

    An improper link following vulnerability was reported in the SmartPerformanceAddin for Lenovo Vantage that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges.

  • CVE-2025-43461MedDec 12, 2025
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Tahoe 26.1. An app may be able to access protected user data.

  • CVE-2025-43381MedDec 12, 2025
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Tahoe 26.1. A malicious app may be able to delete protected user data.