CWE-59
Medium likelihoodImproper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
1,463 vulnerabilities with CWE-59
CVE-2026-41882
HIGH
JetBrains IntelliJ IDEA <2024.3.7.1 - Path Traversal
CVSS 7.4
CVE-2026-7397
MEDIUM
NousResearch hermes-agent file_tools.py _check_sensitive_path symlink
CVSS 4.4
CVE-2026-27105
MEDIUM
Dell/Alienware Purchased Apps < 1.1.31.0 - Arbitrary File Write
CVSS 6.3
CVE-2026-5161
HIGH
Improper Authentication in TUBITAK BILGEM's Pardus About
CVSS 8.8
CVE-2026-41397
MEDIUM
OpenClaw < 2026.3.31 - Sandbox Escape via Unrestricted File Sync and Symlink Traversal
CVSS 6.8
CVE-2026-41364
HIGH
OpenClaw < 2026.3.31 - Arbitrary File Write via Symlink Following in SSH Sandbox Tar Upload
CVSS 8.1
CVE-2026-40977
MEDIUM
Spring Boot <4.0.6 - File Corruption
CVSS 4.7
CVE-2026-41433
HIGH
OpenTelemetry eBPF Instrumentation: Privileged Java agent injection allows arbitrary host file overwrite via untrusted TMPDIR
CVSS 8.4
CVE-2026-6941
MEDIUM
radare2 < 6.1.4 Project Notes Path Traversal via Symlink
CVSS 6.6
CVE-2026-33694
HIGH
Junction File Manipulation
CVE-2026-41231
HIGH
Froxlor has Incomplete Symlink Validation in DataDump.add() that Allows Arbitrary Directory Ownership Takeover via Cron
CVSS 7.5
CVE-2026-35365
MEDIUM
uutils coreutils mv Denial of Service and Data Duplication via Improper Symlink Expansion
CVSS 6.6
CVE-2026-35359
MEDIUM
uutils coreutils cp Information Disclosure via Time-of-Check to Time-of-Use Symlink Swap
CVSS 4.7
CVE-2026-35349
MEDIUM
uutils coreutils Path-Based Safety Bypass with --preserve-root
CVSS 6.7
CVE-2026-35345
MEDIUM
uutils coreutils tail Privileged Information Disclosure via Symlink Replacement Race
CVSS 5.3
CVE-2026-40931
HIGH
Complete Bypass of CVE-2026-24884 Patch via Git-Delivered Symlink Poisoning in compressing
CVSS 8.4
CVE-2026-28684
MEDIUM
python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallback
CVSS 6.6
CVE-2026-34242
HIGH
Weblate: Arbitrary File Read via Symlink
CVSS 7.7
CVE-2026-20161
MEDIUM
Cisco ThousandEyes Enterprise Agent Arbitrary File Overwrite Vulnerability
CVSS 5.5
CVE-2026-4135
MEDIUM
Lenovo Software Fix < 7.5.5.19 - Arbitrary File Write
CVSS 6.6
CVE-2026-0827
HIGH
Lenovo Diagnostics < 5.26.0 - Arbitrary File Write
CVSS 7.1
CVE-2026-32212
MEDIUM
Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability
CVSS 5.5
CVE-2026-35400
LOW
LORIS incorrectly trusts user input in publication module
CVSS 3.5
CVE-2026-32282
MEDIUM
TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix
CVSS 6.4
CVE-2026-27456
MEDIUM
util-linux: TOCTOU Race Condition in util-linux mount(8) - Loop Device Setup
CVSS 4.7
Details
Vulnerabilities
1,463
Exploit Likelihood
Medium