VYPR

CWE-59

Improper Link Resolution Before File Access ('Link Following')

BaseDraftLikelihood: Medium

Description

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76

CVEs mapped to this weakness (1,658)

page 62 of 83
  • CVE-2026-50549CriJun 25, 2026
    risk 0.00cvss 9.8epss 0.01

    Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default. Before a Write, the agent canonicalizes the target path to confirm it stays inside the workspace, but when canonicalization fails it falls back to…

  • CVE-2026-55828Jun 19, 2026
    risk 0.00cvss epss

    ### Impact The go.qbee.io/transport library is affected by a symlink-chain path traversal vulnerability in its extractTar routine. The library's path validation is strictly lexical and fails to account for on-disk symlinks created earlier in the extraction process.…

  • CVE-2026-31894HigMar 11, 2026
    risk 0.00cvss 7.5epss 0.00

    WeGIA is a web manager for charitable institutions. In 3.6.5, The patched loadBackupDB() extracts tar.gz archives to a temporary directory using PHP's PharData class, then uses glob() and file_get_contents() to read SQL files from the extracted contents. Neither the extraction…

  • CVE-2026-23893MedJan 22, 2026
    risk 0.00cvss 6.8epss 0.00

    openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. Versions 2.3.2 and above are vulnerable to symlink-following when running in privileged contexts. A token-group user can redirect file operations to arbitrary filesystem targets by planting symlinks in…

  • CVE-2025-58373MedSep 5, 2025
    risk 0.00cvss 5.5epss 0.00

    Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vulnerability where .rooignore protections could be bypassed using symlinks. This allows an attacker with write access to the workspace to trick the extension…

  • CVE-2025-25185HigMar 3, 2025
    risk 0.00cvss 7.5epss 0.01

    GPT Academic provides interactive interfaces for large language models. In 3.91 and earlier, GPT Academic does not properly account for soft links. An attacker can create a malicious file as a soft link pointing to a target file, then package this soft link file into a tar.gz…

  • CVE-2024-6868CriOct 29, 2024
    risk 0.00cvss 9.8epss 0.02

    mudler/LocalAI version 2.17.1 allows for arbitrary file write due to improper handling of automatic archive extraction. When model configurations specify additional files as archives (e.g., .tar), these archives are automatically extracted after downloading. This behavior can be…

  • CVE-2024-35235MedJun 11, 2024
    risk 0.00cvss 4.4epss 0.02

    OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.8 and earlier, when starting the cupsd server with a Listen configuration item pointing to a symbolic link, the cupsd process can be caused to perform an…

  • CVE-2023-52138HigFeb 5, 2024
    risk 0.00cvss 8.2epss 0.02

    Engrampa is an archive manager for the MATE environment. Engrampa is found to be vulnerable to a Path Traversal vulnerability that can be leveraged to achieve full Remote Command Execution (RCE) on the target. While handling CPIO archives, the Engrampa Archive manager follows…

  • CVE-2022-48579HigAug 7, 2023
    risk 0.00cvss 7.5epss 0.01

    UnRAR before 6.2.3 allows extraction of files outside of the destination folder via symlink chains.

  • CVE-2023-22490MedFeb 14, 2023
    risk 0.00cvss 5.5epss 0.01

    Git is a revision control system. Using a specially-crafted repository, Git prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8 can be tricked into using its local clone optimization even when using a non-local transport. Though…

  • CVE-2022-4563HigDec 16, 2022
    risk 0.00cvss 7.8epss 0.00

    A vulnerability was found in Freedom of the Press SecureDrop. It has been rated as critical. Affected by this issue is some unknown functionality of the file gpg-agent.conf. The manipulation leads to symlink following. Local access is required to approach this attack. The name…

  • CVE-2022-42725HigOct 10, 2022
    risk 0.00cvss 7.5epss 0.01

    Warpinator through 1.2.14 allows access outside of an intended directory, as demonstrated by symbolic directory links.

  • CVE-2021-35939MedAug 26, 2022
    risk 0.00cvss 6.7epss 0.00

    It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges.…

  • CVE-2021-35938MedAug 25, 2022
    risk 0.00cvss 6.7epss 0.01

    A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their…

  • CVE-2021-31566HigAug 23, 2022
    risk 0.00cvss 7.8epss 0.00

    An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to…

  • CVE-2021-23177HigAug 23, 2022
    risk 0.00cvss 7.8epss 0.00

    An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local…

  • CVE-2021-23521MedJan 31, 2022
    risk 0.00cvss 5.5epss 0.01

    This affects the package juce-framework/JUCE before 6.1.5. This vulnerability is triggered when a malicious archive is crafted with an entry containing a symbolic link. When extracted, the symbolic link is followed outside of the target dir allowing writing arbitrary files on…

  • CVE-2021-41072HigSep 14, 2021
    risk 0.00cvss 8.1epss 0.02

    squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link and then contents under the same filename in a filesystem can cause unsquashfs…

  • CVE-2021-32825LowAug 16, 2021
    risk 0.00cvss 2.7epss 0.01

    bblfshd is an open source self-hosted server for source code parsing. In bblfshd before commit 4265465b9b6fb5663c30ee43806126012066aad4 there is a "zipslip" vulnerability. The unsafe handling of symbolic links in an unpacking routine may enable attackers to read and/or write to…