VYPR

CWE-59

Improper Link Resolution Before File Access ('Link Following')

BaseDraftLikelihood: Medium

Description

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76

CVEs mapped to this weakness (1,754)

page 56 of 88
  • CVE-2020-8095MedJan 30, 2020
    risk 0.32cvss 4.9epss 0.00

    A vulnerability in the improper handling of junctions before deletion in Bitdefender Total Security 2020 can allow an attacker to to trigger a denial of service on the affected device.

  • CVE-2026-54587MedSep 17, 2026
    risk 0.31cvss —epss 0.00

    mport is the MidnightBSD Package Manager. Prior to 2.7.8, directory assets handled as ASSET_DIR or ASSET_DIR_OWNER_MODE in libmport/bundle_read_install_pkg.c used path-based mport_mkdirp(), ownership, and permission operations. A local attacker able to modify part of the target…

  • CVE-2026-54576MedSep 17, 2026
    risk 0.31cvss —epss 0.00

    mport is the MidnightBSD Package Manager. Prior to 2.7.8, do_actual_install() in libmport/bundle_read_install_pkg.c used path-based lstat(), chown(), stat(), and chmod() operations while installing package files. A local attacker with write access to a target directory could…

  • CVE-2026-86861MedSep 17, 2026
    risk 0.31cvss 5.9epss 0.00

    pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested path with Filemanager.check_access_permission() and then opened the file for writing with a plain open() call. CVE-2026-7819 had previously hardened the separate…

  • CVE-2026-69771MedSep 8, 2026
    risk 0.31cvss 4.7epss 0.00

    Improper link resolution before file access ('link following') in Windows Container Manager Service allows an authorized attacker to bypass a security feature locally.

  • CVE-2026-69425MedSep 8, 2026
    risk 0.31cvss 4.7epss 0.00

    Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to perform tampering locally.

  • CVE-2026-79676MedAug 25, 2026
    risk 0.31cvss 5.9epss 0.00

    NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen root-derived paths using built-in open() instead of nltk.pathsec.open(), allowing symlinks to escape trusted roots. Attackers who stage symlinked corpus files under a trusted data…

  • CVE-2026-71493MedAug 21, 2026
    risk 0.31cvss —epss 0.00

    Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, the readFile, pathExists, isDir, and matchPaths template functions in internal/config/template/parser.go use a lexical filepath.Rel check and a leaf-only os.Lstat check that…

  • CVE-2026-53801MedAug 13, 2026
    risk 0.31cvss 5.9epss 0.00

    rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's directory scanning logic that allows attackers to cause the sender to enumerate and transfer files outside the module root's intended subtree. Attackers who can create or manipulate symlinks in a…

  • CVE-2026-40977MedApr 28, 2026
    risk 0.31cvss 4.7epss 0.00

    When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location can corrupt one file on the host each time the application is started. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix…

  • CVE-2026-35359MedApr 22, 2026
    risk 0.31cvss 4.7epss 0.00

    A Time-of-Check to Time-of-Use (TOCTOU) vulnerability in the cp utility of uutils coreutils allows an attacker to bypass no-dereference intent. The utility checks if a source path is a symbolic link using path-based metadata but subsequently opens it without the O_NOFOLLOW flag.…

  • CVE-2026-21517MedFeb 10, 2026
    risk 0.31cvss 4.7epss 0.00

    Improper link resolution before file access ('link following') in Windows App for Mac allows an authorized attacker to elevate privileges locally.

  • CVE-2025-41421MedOct 1, 2025
    risk 0.31cvss 4.7epss 0.00

    Improper handling of symbolic links in the TeamViewer Full Client and Host for Windows — in versions prior to 15.70 of TeamViewer Remote and Tensor — allows an attacker with local, unprivileged access to a device lacking adequate malware protection to escalate privileges by…

  • CVE-2025-8869MedSep 24, 2025
    risk 0.31cvss —epss 0.00

    When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by…

  • CVE-2023-24572MedFeb 13, 2023
    risk 0.31cvss 4.7epss 0.00

    Dell Command | Integration Suite for System Center, versions before 6.4.0 contain an arbitrary folder delete vulnerability during uninstallation. A locally authenticated malicious user may potentially exploit this vulnerability leading to arbitrary folder deletion.

  • CVE-2023-23697MedFeb 13, 2023
    risk 0.31cvss 4.7epss 0.00

    Dell Command | Intel vPro Out of Band, versions before 4.4.0, contain an arbitrary folder delete vulnerability during uninstallation. A locally authenticated malicious user may potentially exploit this vulnerability leading to arbitrary folder deletion.

  • CVE-2020-4885MedJun 24, 2021
    risk 0.31cvss 4.7epss 0.00

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow a local user to access and change the configuration of Db2 due to a race condition of a symbolic link,. IBM X-Force ID: 190909.

  • CVE-2011-1136MedNov 14, 2019
    risk 0.31cvss 4.7epss 0.00

    In tesseract 2.03 and 2.04, an attacker can rewrite an arbitrary user file by guessing the PID and creating a link to the user's file.

  • CVE-2010-3095MedNov 12, 2019
    risk 0.31cvss 4.7epss 0.00

    mailscanner before 4.79.11-2.1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files. NOTE: this issue exists because of an incomplete fix for CVE-2008-5313.

  • CVE-2018-14329MedJul 17, 2018
    risk 0.31cvss 4.7epss 0.00

    In HTSlib 1.8, a race condition in cram/cram_io.c might allow local users to overwrite arbitrary files via a symlink attack.