VYPR

CWE-59

Improper Link Resolution Before File Access ('Link Following')

BaseDraftLikelihood: Medium

Description

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76

CVEs mapped to this weakness (1,754)

page 54 of 88
  • CVE-2026-34883MedMay 19, 2026
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in the Portrait Dell Color Management application before 3.7.0 for Dell monitors. On Windows, a symbolic link vulnerability allows a local low-privileged user to escalate privileges to Administrator. During installation, the software writes the file…

  • CVE-2026-35356MedApr 22, 2026
    risk 0.34cvss 6.3epss 0.00

    A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the install utility of uutils coreutils when using the -D flag. The command creates parent directories and subsequently performs a second path resolution to create the target file, neither of which is anchored to a…

  • CVE-2026-35355MedApr 22, 2026
    risk 0.34cvss 6.3epss 0.00

    The install utility in uutils coreutils is vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition during file installation. The implementation unlinks an existing destination file and then recreates it using a path-based operation without the O_EXCL flag. A local…

  • CVE-2026-35345MedApr 22, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in the tail utility of uutils coreutils allows for the exfiltration of sensitive file contents when using the --follow=name option. Unlike GNU tail, the uutils implementation continues to monitor a path after it has been replaced by a symbolic link, subsequently…

  • CVE-2026-28689MedMar 10, 2026
    risk 0.34cvss 6.3epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, domain="path" authorization is checked before final file open/use. A symlink swap between check-time and use-time bypasses policy-denied…

  • CVE-2026-29786MedMar 7, 2026
    risk 0.34cvss 6.3epss 0.00

    node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as C:../target.txt, which enables file overwrite outside cwd during normal…

  • CVE-2026-24047MedJan 21, 2026
    risk 0.34cvss 6.3epss 0.01

    Backstage is an open framework for building developer portals, and @backstage/cli-common provides config loading functionality used by the backend and command line interface of Backstage. Prior to version 0.1.17, the `resolveSafeChildPath` utility function in…

  • CVE-2025-68146MedDec 16, 2025
    risk 0.34cvss 6.3epss 0.00

    filelock is a platform-independent file lock for Python. In versions prior to 3.20.1, a Time-of-Check-Time-of-Use (TOCTOU) race condition allows local attackers to corrupt or truncate arbitrary user files through symlink attacks. The vulnerability exists in both Unix and Windows…

  • CVE-2023-41971MedMay 2, 2024
    risk 0.34cvss 5.3epss 0.00

    An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Windows allows a system file to be overwritten.This issue affects Client Connector on Windows: before 3.7.

  • CVE-2024-21397MedFeb 13, 2024
    risk 0.34cvss 5.3epss 0.01

    Microsoft Azure File Sync Elevation of Privilege Vulnerability

  • CVE-2021-32557MedJun 12, 2021
    risk 0.34cvss 5.2epss 0.00

    It was discovered that the process_report() function in data/whoopsie-upload-all allowed arbitrary file writes via symlinks.

  • CVE-2015-0796MedMar 2, 2018
    risk 0.34cvss 6.3epss 0.01

    In open buildservice 2.6 before 2.6.3, 2.5 before 2.5.7 and 2.4 before 2.4.8 the source service patch application could generate non-standard files like symlinks or device nodes, which could allow buildservice users to break of confinement or cause denial of service attacks on…

  • CVE-2026-59944MedSep 16, 2026
    risk 0.33cvss 6.1epss 0.00

    Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and from 2.3.0 until 2.10.3, a malicious or compromised dependency can bypass the earlier CVE-2026-59946 binary-path hardening because Composer validates literal parent-directory segments only during…

  • CVE-2026-70626MedAug 22, 2026
    risk 0.33cvss 6.2epss 0.00

    NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to read arbitrary files outside the corpus root. The vulnerability exists because path validation is lexical and does not account for symlink resolution, enabling…

  • CVE-2026-74796MedAug 16, 2026
    risk 0.33cvss 6.1epss 0.00

    OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious symlink in a trusted working directory to cause tofu init to write provider package contents to arbitrary filesystem locations…

  • CVE-2025-30240MedAug 10, 2026
    risk 0.33cvss —epss 0.00

    The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage devices. By placing a crafted symbolic link on supported storage media, an attacker may cause the system to resolve the link. Successful exploitation may allow…

  • CVE-2026-47121MedJul 21, 2026
    risk 0.33cvss 6.1epss 0.00

    Sparkle is a software update framework for macOS. Prior to version 2.9.2, `Autoupdate/SUBinaryDeltaApply.m` enforces `relativePath.pathComponents containsObject:@".."` and rejects writes whose immediate parent directory IS itself a symbolic link, but does not detect symlinks…

  • CVE-2026-53766MedJun 24, 2026
    risk 0.33cvss 6.1epss 0.00

    Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From 0.24.0 until 1.1.0, McpContext.validatePath() enforces workspace roots by checking whether path.resolve(filePath) textually falls under one of the configured…

  • CVE-2026-53765MedJun 24, 2026
    risk 0.33cvss 6.1epss 0.00

    Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From 0.20.0 until 1.1.0, The chrome-devtools-mcp daemon writes its PID file with fs.writeFileSync() to a deterministic runtime path. On typical macOS environments,…

  • CVE-2026-6892MedMay 29, 2026
    risk 0.33cvss 5.0epss 0.00

    Improper handling of symbolic links in the installer of CUPS Printer Driver for macOS(*) may allow a local attacker with login privileges to exploit a specially crafted symbolic link during installation to modify permissions of directories for which they would not normally have…