CWE-59
Medium likelihoodImproper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
1,612 vulnerabilities with CWE-59
CVE-2026-16077
MEDIUM
AstrBotDevs AstrBot Filesystem Computer-Use Tool fs.py _normalize_rw_path link following
CVSS 5.3
CVE-2026-50163
HIGH
oras-go: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution in `oras-go` tar extraction
CVSS 7.1
CVE-2026-53535
MEDIUM
Activepieces: Arbitrary file write in git-sync via path traversal and symlinks
CVE-2026-12391
MEDIUM
ubuntu-pro-client Local Privilege Escalation and Information Disclosure via Symlink Arbitrary File Read in collect-logs
CVSS 5.0
CVE-2026-61371
HIGH
Microsoft AVML < 0.17.0 - Arbitrary File Truncation via Symlink Following in Output Path
CVSS 7.5
CVE-2026-61859
LOW
ImageMagick before 7.1.2-26 Policy Bypass via script operation
CVSS 3.3
CVE-2026-54572
HIGH
rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote
CVSS 7.5
CVE-2026-53486
CRITICAL
decompress: Archive extraction can create files and links outside the target directory
CVSS 9.1
CVE-2026-50526
HIGH
Microsoft .NET 10.0 - .NET Tampering Vulnerability
CVSS 7.0
CVE-2026-50469
HIGH
Microsoft Windows 10 Version 1809 - Windows Projected File System Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-50438
HIGH
Microsoft PC Manager Elevation of Privilege Vulnerability
CVSS 8.8
CVE-2026-58636
HIGH
Microsoft PC Manager Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-50364
HIGH
Microsoft Windows 10 Version 21H2 - Windows Backup Service Elevation of Privilege Vulnerability
CVSS 7.3
CVE-2026-49791
HIGH
Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability
CVSS 7.1
CVE-2026-49180
MEDIUM
Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability
CVSS 5.5
CVE-2026-49176
HIGH
Microsoft Windows 10 Version 1607 - Windows WalletService Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-15392
HIGH
DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location
CVSS 7.7
CVE-2026-6851
HIGH
Improper link resolution before file access in Bitdefender Total Security via Link Following (VA-13681)
CVE-2026-15629
MEDIUM
louisho5 picobot Workspace filesystem.go GetSkill link following
CVSS 6.3
CVE-2026-15621
MEDIUM
mosaxiv clawlet File Tools fs_ops.go edit_file link following
CVSS 5.3
CVE-2026-62239
MEDIUM
FlashAttention Symlink Attack via tarfile.extractall in hopper/setup.py
CVSS 6.6
CVE-2026-62189
HIGH
OpenClaw < 2026.6.9 Symlink Following via Mirror Sync
CVSS 7.1
CVE-2026-15684
HIGH
Glarysoft Glary Utilities Link Following Local Privilege Escalation Vulnerability
CVSS 7.3
CVE-2026-15682
MEDIUM
AnyDesk Support Information Link Following Denial-of-Service Vulnerability
CVSS 5.5
CVE-2026-15681
MEDIUM
AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability
CVSS 5.5
Details
Vulnerabilities
1,612
Exploit Likelihood
Medium