CWE-59

Medium likelihood

Improper Link Resolution Before File Access ('Link Following')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,612 vulnerabilities with CWE-59
CVE-2026-61858 LOW
ImageMagick before 7.1.2-26 Policy Bypass via APNG encoder
CVSS 3.3
CVE-2026-39246 HIGH
decompress < 4.2.2 - Arbitrary Symlink Creation via Unvalidated Archive Symlink Entries
CVSS 7.5
CVE-2026-39243 MEDIUM
decompress < 4.2.2 - Arbitrary Hardlink Creation and File Disclosure via Archive Extraction
CVSS 5.5
CVE-2026-58198 MEDIUM
ChatterBot: Symlink-Following Arbitrary Write via UbuntuCorpusTrainer
CVSS 5.5
CVE-2026-14891 HIGH
Nomad vulnerable to sandbox escape in Docker task driver
CVSS 8.7
CVE-2026-14361 MEDIUM
Consul-template is vulnerable to path redirection in writeToFile through symlink attack
CVSS 4.7
CVE-2026-14966 LOW
Symlink guard bypass in unarchive module allows planting symlinks during extraction
CVSS 3.1
CVE-2026-55668 MEDIUM
File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope
CVSS 6.3
CVE-2026-14904 MEDIUM
AWS RES 2026.03 - Auth.GetUserPrivateKey Arbitrary File Read
CVSS 6.5
CVE-2026-57571 CRITICAL
Crawl4AI arbitrary file write via download filename path traversal
CVSS 9.6
CVE-2026-50135 MEDIUM
Hugo: Symlink confinement bypass in resources.Get
CVSS 5.5
CVE-2026-58403 MEDIUM
Hugo symlink confinement bypass in os.ReadFile
CVSS 6.5
CVE-2026-58203 MEDIUM
NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size
CVSS 5.3
CVE-2026-14699 LOW
zcaceres markdownify-mcp Markdownify.ts assertPathAllowed symlink
CVSS 3.3
CVE-2026-57991 HIGH
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVSS 7.4
CVE-2026-25718 CRITICAL
Gitea template repository generation mishandles symlinked paths
CVSS 9.1
CVE-2026-46464 MEDIUM
Dell PowerProtect Data Domain - Improper Link Resolution Before File Access ('Link Following')
CVSS 4.9
CVE-2026-46468 MEDIUM
Dell PowerProtect Data Domain - Improper Link Resolution Before File Access ('Link Following')
CVSS 4.4
CVE-2026-44269 MEDIUM
Dell PowerProtect Data Domain - Improper Link Resolution Before File Access ('Link Following')
CVSS 4.4
CVE-2026-41121 HIGH
Dell Device Management Agent < 26.05 - Improper Link Resolution Before File Access ('Link Following')
CVSS 7.3
CVE-2026-55607 HIGH
Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
CVSS 8.8
CVE-2026-46406 MEDIUM
Claude Code: Insecure Temporary File in /copy Command Enables Response Disclosure and Symlink-Based File Write
CVSS 6.1
CVE-2026-54371 HIGH
attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattr
CVSS 7.1
CVE-2026-54369 HIGH
acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functions
CVSS 7.1
CVE-2026-54352 CRITICAL
Budibase: Arbitrary file read by workspace-builder via PWA-zip symlink upload
CVSS 9.6
Details
Vulnerabilities 1,612
Exploit Likelihood Medium