CWE-59

Medium likelihood

Improper Link Resolution Before File Access ('Link Following')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,463 vulnerabilities with CWE-59
CVE-2026-41882 HIGH
JetBrains IntelliJ IDEA <2024.3.7.1 - Path Traversal
CVSS 7.4
CVE-2026-7397 MEDIUM
NousResearch hermes-agent file_tools.py _check_sensitive_path symlink
CVSS 4.4
CVE-2026-27105 MEDIUM
Dell/Alienware Purchased Apps < 1.1.31.0 - Arbitrary File Write
CVSS 6.3
CVE-2026-5161 HIGH
Improper Authentication in TUBITAK BILGEM's Pardus About
CVSS 8.8
CVE-2026-41397 MEDIUM
OpenClaw < 2026.3.31 - Sandbox Escape via Unrestricted File Sync and Symlink Traversal
CVSS 6.8
CVE-2026-41364 HIGH
OpenClaw < 2026.3.31 - Arbitrary File Write via Symlink Following in SSH Sandbox Tar Upload
CVSS 8.1
CVE-2026-40977 MEDIUM
Spring Boot <4.0.6 - File Corruption
CVSS 4.7
CVE-2026-41433 HIGH
OpenTelemetry eBPF Instrumentation: Privileged Java agent injection allows arbitrary host file overwrite via untrusted TMPDIR
CVSS 8.4
CVE-2026-6941 MEDIUM
radare2 < 6.1.4 Project Notes Path Traversal via Symlink
CVSS 6.6
CVE-2026-33694 HIGH
Junction File Manipulation
CVE-2026-41231 HIGH
Froxlor has Incomplete Symlink Validation in DataDump.add() that Allows Arbitrary Directory Ownership Takeover via Cron
CVSS 7.5
CVE-2026-35365 MEDIUM
uutils coreutils mv Denial of Service and Data Duplication via Improper Symlink Expansion
CVSS 6.6
CVE-2026-35359 MEDIUM
uutils coreutils cp Information Disclosure via Time-of-Check to Time-of-Use Symlink Swap
CVSS 4.7
CVE-2026-35349 MEDIUM
uutils coreutils Path-Based Safety Bypass with --preserve-root
CVSS 6.7
CVE-2026-35345 MEDIUM
uutils coreutils tail Privileged Information Disclosure via Symlink Replacement Race
CVSS 5.3
CVE-2026-40931 HIGH
Complete Bypass of CVE-2026-24884 Patch via Git-Delivered Symlink Poisoning in compressing
CVSS 8.4
CVE-2026-28684 MEDIUM
python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallback
CVSS 6.6
CVE-2026-34242 HIGH
Weblate: Arbitrary File Read via Symlink
CVSS 7.7
CVE-2026-20161 MEDIUM
Cisco ThousandEyes Enterprise Agent Arbitrary File Overwrite Vulnerability
CVSS 5.5
CVE-2026-4135 MEDIUM
Lenovo Software Fix < 7.5.5.19 - Arbitrary File Write
CVSS 6.6
CVE-2026-0827 HIGH
Lenovo Diagnostics < 5.26.0 - Arbitrary File Write
CVSS 7.1
CVE-2026-32212 MEDIUM
Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability
CVSS 5.5
CVE-2026-35400 LOW
LORIS incorrectly trusts user input in publication module
CVSS 3.5
CVE-2026-32282 MEDIUM
TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix
CVSS 6.4
CVE-2026-27456 MEDIUM
util-linux: TOCTOU Race Condition in util-linux mount(8) - Loop Device Setup
CVSS 4.7
Details
Vulnerabilities 1,463
Exploit Likelihood Medium