VYPR

CWE-59

Improper Link Resolution Before File Access ('Link Following')

BaseDraftLikelihood: Medium

Description

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76

CVEs mapped to this weakness (1,754)

page 44 of 88
  • CVE-2015-5700MedAug 25, 2017
    risk 0.40cvss 6.1epss 0.00

    mktexlsr revision 22855 through revision 36625 as packaged in texlive allows local users to write to arbitrary files via a symlink attack.

  • CVE-2026-88016HigSep 10, 2026
    risk 0.39cvss 7.1epss 0.00

    rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, when backend/local runs with --links, a source .rclonelink object can plant a symlink in the destination and later directory metadata is applied through…

  • CVE-2026-78622MedSep 8, 2026
    risk 0.39cvss 6.0epss 0.00

    The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges. The delete operation follows the junction target, resulting in recursive deletion of unintended directory…

  • CVE-2026-81727HigAug 27, 2026
    risk 0.39cvss 7.1epss 0.00

    NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardlinks. Attackers with write access to a…

  • CVE-2026-81726HigAug 27, 2026
    risk 0.39cvss 7.0epss 0.00

    NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. Attackers can read or write files outside allowed sandbox roots through TransitionParser,…

  • CVE-2026-49114HigAug 21, 2026
    risk 0.39cvss 7.1epss 0.00

    In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_data location field and opens it for writing without 'O_NOFOLLOW/O_EXCL', after a non-atomic 'os.path.isfile()' check. A local attacker with write access to the…

  • CVE-2026-17106HigAug 18, 2026
    risk 0.39cvss —epss 0.00

    The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extractor decides where each archive entry lands using lexical string checks and then…

  • CVE-2026-53785HigAug 13, 2026
    risk 0.39cvss 7.1epss 0.00

    rsync before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to write files outside the intended destination directory tree by crafting relative paths with symlink components in --relative mode. The make_path() function follows symlinks pointing…

  • CVE-2026-53784HigAug 13, 2026
    risk 0.39cvss 7.1epss 0.00

    rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intended module root when use chroot is disabled and the module root path or a component of it is a symlink. The daemon calls chdir() to the module root at session…

  • CVE-2026-71556HigAug 7, 2026
    risk 0.39cvss 7.1epss 0.00

    go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution to the worktree boundary, so a…

  • CVE-2026-50163HigJul 17, 2026
    risk 0.39cvss 7.1epss 0.00

    oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/utils.go:262-275 validates a hardlink target relative to the extract base but returns the unresolved target, causing os.Link("victim.secret", "<extract_base>/payload.tar.gz/evil_cwd…

  • CVE-2026-55607HigJun 29, 2026
    risk 0.39cvss 8.8epss 0.01

    Claude Code is an agentic coding tool. From 2.1.38 until 2.1.163, Claude Code's worktree handling allowed creation of worktrees named ".git" and navigation to worktrees outside the sandbox context, enabling git directory confusion attacks. By exploiting symlink manipulation and…

  • CVE-2026-28262MedJun 9, 2026
    risk 0.39cvss 6.0epss 0.00

    Dell iDRAC Tools, versions prior to 11.4.1.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.

  • CVE-2026-49135HigJun 1, 2026
    risk 0.39cvss 7.1epss 0.00

    CodexBar prior to 0.32.0 contains an insecure temporary file handling vulnerability that allows local attackers to access sensitive credentials or tamper with build artifacts by exploiting predictable file paths in the release notarization workflow. Attackers with access to the…

  • CVE-2026-34604HigApr 1, 2026
    risk 0.39cvss 7.1epss 0.00

    Tina is a headless content management system. Prior to version 2.2.2, @tinacms/graphql uses string-based path containment checks in FilesystemBridge. That blocks plain ../ traversal, but it does not resolve symlink or junction targets. If a symlink/junction already exists under…

  • CVE-2026-34603HigApr 1, 2026
    risk 0.39cvss 7.1epss 0.00

    Tina is a headless content management system. Prior to version 2.2.2, @tinacms/cli recently added lexical path-traversal checks to the dev media routes, but the implementation still validates only the path string and does not resolve symlink or junction targets. If a link…

  • CVE-2026-24046HigJan 21, 2026
    risk 0.39cvss 7.1epss 0.01

    Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder templates could exploit symlinks to read…

  • CVE-2025-21195MedJul 8, 2025
    risk 0.39cvss 6.0epss 0.00

    Improper link resolution before file access ('link following') in Service Fabric allows an authorized attacker to elevate privileges locally.

  • CVE-2025-21347MedFeb 11, 2025
    risk 0.39cvss 6.0epss 0.01

    Windows Deployment Services Denial of Service Vulnerability

  • CVE-2025-21188MedFeb 11, 2025
    risk 0.39cvss 6.0epss 0.01

    Azure Network Watcher VM Extension Elevation of Privilege Vulnerability