CWE-59

Medium likelihood

Improper Link Resolution Before File Access ('Link Following')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,612 vulnerabilities with CWE-59
CVE-2026-16077 MEDIUM
AstrBotDevs AstrBot Filesystem Computer-Use Tool fs.py _normalize_rw_path link following
CVSS 5.3
CVE-2026-50163 HIGH
oras-go: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution in `oras-go` tar extraction
CVSS 7.1
CVE-2026-53535 MEDIUM
Activepieces: Arbitrary file write in git-sync via path traversal and symlinks
CVE-2026-12391 MEDIUM
ubuntu-pro-client Local Privilege Escalation and Information Disclosure via Symlink Arbitrary File Read in collect-logs
CVSS 5.0
CVE-2026-61371 HIGH
Microsoft AVML < 0.17.0 - Arbitrary File Truncation via Symlink Following in Output Path
CVSS 7.5
CVE-2026-61859 LOW
ImageMagick before 7.1.2-26 Policy Bypass via script operation
CVSS 3.3
CVE-2026-54572 HIGH
rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote
CVSS 7.5
CVE-2026-53486 CRITICAL
decompress: Archive extraction can create files and links outside the target directory
CVSS 9.1
CVE-2026-50526 HIGH
Microsoft .NET 10.0 - .NET Tampering Vulnerability
CVSS 7.0
CVE-2026-50469 HIGH
Microsoft Windows 10 Version 1809 - Windows Projected File System Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-50438 HIGH
Microsoft PC Manager Elevation of Privilege Vulnerability
CVSS 8.8
CVE-2026-58636 HIGH
Microsoft PC Manager Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-50364 HIGH
Microsoft Windows 10 Version 21H2 - Windows Backup Service Elevation of Privilege Vulnerability
CVSS 7.3
CVE-2026-49791 HIGH
Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability
CVSS 7.1
CVE-2026-49180 MEDIUM
Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability
CVSS 5.5
CVE-2026-49176 HIGH
Microsoft Windows 10 Version 1607 - Windows WalletService Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-15392 HIGH
DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location
CVSS 7.7
CVE-2026-6851 HIGH
Improper link resolution before file access in Bitdefender Total Security via Link Following (VA-13681)
CVE-2026-15629 MEDIUM
louisho5 picobot Workspace filesystem.go GetSkill link following
CVSS 6.3
CVE-2026-15621 MEDIUM
mosaxiv clawlet File Tools fs_ops.go edit_file link following
CVSS 5.3
CVE-2026-62239 MEDIUM
FlashAttention Symlink Attack via tarfile.extractall in hopper/setup.py
CVSS 6.6
CVE-2026-62189 HIGH
OpenClaw < 2026.6.9 Symlink Following via Mirror Sync
CVSS 7.1
CVE-2026-15684 HIGH
Glarysoft Glary Utilities Link Following Local Privilege Escalation Vulnerability
CVSS 7.3
CVE-2026-15682 MEDIUM
AnyDesk Support Information Link Following Denial-of-Service Vulnerability
CVSS 5.5
CVE-2026-15681 MEDIUM
AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability
CVSS 5.5
Details
Vulnerabilities 1,612
Exploit Likelihood Medium