CWE-59
Improper Link Resolution Before File Access ('Link Following')
Description
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76
CVEs mapped to this weakness (1,754)
page 55 of 88| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-6891 | Med | 0.33 | 5.0 | 0.00 | May 29, 2026 | Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a local attacker with login privileges to exploit a specially crafted symbolic link during installation to modify permissions of files for which they would not… | ||
| CVE-2026-31990 | Med | 0.33 | 6.1 | 0.00 | Mar 19, 2026 | OpenClaw versions prior to 2026.3.2 contain a vulnerability in the stageSandboxMedia function in which it fails to validate destination symlinks during media staging, allowing writes to follow symlinks outside the sandbox workspace. Attackers can exploit this by placing symlinks… | ||
| CVE-2026-27545 | Med | 0.33 | 6.1 | 0.00 | Mar 18, 2026 | OpenClaw versions prior to 2026.2.26 contain an approval bypass vulnerability in system.run execution that allows attackers to execute commands from unintended filesystem locations by rebinding writable parent symlinks in the current working directory after approval. An attacker… | ||
| CVE-2026-27523 | Med | 0.33 | 6.1 | 0.00 | Mar 18, 2026 | OpenClaw versions prior to 2026.2.24 contain a sandbox bind validation vulnerability allowing attackers to bypass allowed-root and blocked-path checks via symlinked parent directories with non-existent leaf paths. Attackers can craft bind source paths that appear within allowed… | ||
| CVE-2025-15328 | Med | 0.33 | 5.0 | 0.00 | Feb 5, 2026 | Tanium addressed an improper link resolution before file access vulnerability in Enforce. | ||
| CVE-2023-40028 | Med | 0.33 | 4.9 | 0.69 | Aug 15, 2023 | Ghost is an open source content management system. Versions prior to 5.59.1 are subject to a vulnerability which allows authenticated users to upload files that are symlinks. This can be exploited to perform an arbitrary file read of any file on the host operating system. Site… | ||
| CVE-2023-28642 | Med | 0.33 | 6.1 | 0.00 | Mar 29, 2023 | runc is a CLI tool for spawning and running containers according to the OCI specification. It was found that AppArmor can be bypassed when `/proc` inside the container is symlinked with a specific mount configuration. This issue has been fixed in runc version 1.1.5, by… | ||
| CVE-2023-21722 | Med | 0.33 | 5.0 | 0.01 | Feb 14, 2023 | .NET Framework Denial of Service Vulnerability | ||
| CVE-2022-42292 | Med | 0.33 | 5.0 | 0.00 | Feb 12, 2023 | NVIDIA GeForce Experience contains a vulnerability in the NVContainer component, where a user without administrator privileges can create a symbolic link to a file that requires elevated privileges to write to or modify, which may lead to denial of service, escalation of… | ||
| CVE-2021-42297 | Med | 0.33 | 5.0 | 0.01 | Nov 24, 2021 | Windows 10 Update Assistant Elevation of Privilege Vulnerability | ||
| CVE-2020-26277 | Med | 0.33 | 6.1 | 0.01 | Dec 21, 2020 | DBdeployer is a tool that deploys MySQL database servers easily. In DBdeployer before version 1.58.2, users unpacking a tarball may use a maliciously packaged tarball that contains symlinks to files external to the target. In such scenario, an attacker could induce dbdeployer to… | ||
| CVE-2019-18901 | Med | 0.33 | 5.1 | 0.00 | Mar 2, 2020 | A UNIX Symbolic Link (Symlink) Following vulnerability in the mysql-systemd-helper of the mariadb packaging of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allows local attackers to change the permissions of arbitrary files to 0640. This issue affects: SUSE… | ||
| CVE-2013-1866 | Med | 0.33 | 6.1 | 0.00 | Jan 30, 2020 | OpenSC OpenSC.tokend has an Arbitrary File Creation/Overwrite Vulnerability | ||
| CVE-2019-3902 | Med | 0.33 | 5.1 | 0.01 | Apr 22, 2019 | A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository. | ||
| CVE-2013-4392 | Med | 0.33 | 5.0 | 0.00 | Oct 28, 2013 | systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files. | ||
| CVE-2026-55828 | Med | 0.32 | — | 0.00 | Sep 15, 2026 | qbee transport is a remote access transport protocol implementation. Prior to 1.26.25, the extractTar routine uses strictly lexical path validation that does not account for on-disk symlinks created earlier in the extraction process. A crafted tar archive can use a symlink chain… | ||
| CVE-2026-8052 | Med | 0.32 | 6.0 | 0.00 | May 12, 2026 | HashiCorp Nomad’s exec2 task driver prior to 0.1.2 is vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-8052) is fixed in version 0.1.2 of the exec2 task driver. | ||
| CVE-2026-6959 | Med | 0.32 | 6.0 | 0.00 | May 12, 2026 | HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-6959) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11. | ||
| CVE-2021-41551 | Med | 0.32 | 4.9 | 0.01 | Jan 18, 2022 | Leostream Connection Broker 9.0.40.17 allows administrators to conduct directory traversal attacks by uploading z ZIP file that contains a symbolic link. | ||
| CVE-2020-3223 | Med | 0.32 | 4.9 | 0.02 | Jun 3, 2020 | A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker with administrative privileges to read arbitrary files on the underlying filesystem of the device. The vulnerability is due to insufficient file scope… |
- risk 0.33cvss 5.0epss 0.00
Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a local attacker with login privileges to exploit a specially crafted symbolic link during installation to modify permissions of files for which they would not…
- risk 0.33cvss 6.1epss 0.00
OpenClaw versions prior to 2026.3.2 contain a vulnerability in the stageSandboxMedia function in which it fails to validate destination symlinks during media staging, allowing writes to follow symlinks outside the sandbox workspace. Attackers can exploit this by placing symlinks…
- risk 0.33cvss 6.1epss 0.00
OpenClaw versions prior to 2026.2.26 contain an approval bypass vulnerability in system.run execution that allows attackers to execute commands from unintended filesystem locations by rebinding writable parent symlinks in the current working directory after approval. An attacker…
- risk 0.33cvss 6.1epss 0.00
OpenClaw versions prior to 2026.2.24 contain a sandbox bind validation vulnerability allowing attackers to bypass allowed-root and blocked-path checks via symlinked parent directories with non-existent leaf paths. Attackers can craft bind source paths that appear within allowed…
- risk 0.33cvss 5.0epss 0.00
Tanium addressed an improper link resolution before file access vulnerability in Enforce.
- risk 0.33cvss 4.9epss 0.69
Ghost is an open source content management system. Versions prior to 5.59.1 are subject to a vulnerability which allows authenticated users to upload files that are symlinks. This can be exploited to perform an arbitrary file read of any file on the host operating system. Site…
- risk 0.33cvss 6.1epss 0.00
runc is a CLI tool for spawning and running containers according to the OCI specification. It was found that AppArmor can be bypassed when `/proc` inside the container is symlinked with a specific mount configuration. This issue has been fixed in runc version 1.1.5, by…
- risk 0.33cvss 5.0epss 0.01
.NET Framework Denial of Service Vulnerability
- risk 0.33cvss 5.0epss 0.00
NVIDIA GeForce Experience contains a vulnerability in the NVContainer component, where a user without administrator privileges can create a symbolic link to a file that requires elevated privileges to write to or modify, which may lead to denial of service, escalation of…
- risk 0.33cvss 5.0epss 0.01
Windows 10 Update Assistant Elevation of Privilege Vulnerability
- risk 0.33cvss 6.1epss 0.01
DBdeployer is a tool that deploys MySQL database servers easily. In DBdeployer before version 1.58.2, users unpacking a tarball may use a maliciously packaged tarball that contains symlinks to files external to the target. In such scenario, an attacker could induce dbdeployer to…
- risk 0.33cvss 5.1epss 0.00
A UNIX Symbolic Link (Symlink) Following vulnerability in the mysql-systemd-helper of the mariadb packaging of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allows local attackers to change the permissions of arbitrary files to 0640. This issue affects: SUSE…
- risk 0.33cvss 6.1epss 0.00
OpenSC OpenSC.tokend has an Arbitrary File Creation/Overwrite Vulnerability
- risk 0.33cvss 5.1epss 0.01
A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.
- risk 0.33cvss 5.0epss 0.00
systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.
- risk 0.32cvss —epss 0.00
qbee transport is a remote access transport protocol implementation. Prior to 1.26.25, the extractTar routine uses strictly lexical path validation that does not account for on-disk symlinks created earlier in the extraction process. A crafted tar archive can use a symlink chain…
- risk 0.32cvss 6.0epss 0.00
HashiCorp Nomad’s exec2 task driver prior to 0.1.2 is vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-8052) is fixed in version 0.1.2 of the exec2 task driver.
- risk 0.32cvss 6.0epss 0.00
HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-6959) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.
- risk 0.32cvss 4.9epss 0.01
Leostream Connection Broker 9.0.40.17 allows administrators to conduct directory traversal attacks by uploading z ZIP file that contains a symbolic link.
- risk 0.32cvss 4.9epss 0.02
A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker with administrative privileges to read arbitrary files on the underlying filesystem of the device. The vulnerability is due to insufficient file scope…