CWE-59

Medium likelihood

Improper Link Resolution Before File Access ('Link Following')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,612 vulnerabilities with CWE-59
CVE-2026-45405 CRITICAL
Dokku: Arbitrary File Write via Tar Symlink Traversal in git:from-archive and certs:add
CVSS 9.0
CVE-2026-55667 HIGH
File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup
CVSS 8.2
CVE-2026-54094 HIGH
File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope
CVSS 7.5
CVE-2026-50549 CRITICAL
Cursor Desktop sandbox escape via symlink and failed path canonicalization
CVSS 9.8
CVE-2026-53766 MEDIUM
chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots
CVSS 6.1
CVE-2026-53765 MEDIUM
chrome-devtools-mcp: daemon.pid write follows symlinks in /tmp fallback runtime directory
CVSS 6.1
CVE-2026-52811 CRITICAL
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym
CVE-2026-23879 HIGH
py7zr: Arbitrary File Write Vulnerability
CVSS 8.0
CVE-2026-35025 HIGH
ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR
CVSS 8.1
CVE-2026-11940 HIGH
tarfile extraction filter bypass allows escaping the destination directory
CVE-2026-56692 MEDIUM
NanoClaw < 2.1.17 - Arbitrary File Read via Symlink Following in forwardAttachedFiles
CVSS 5.5
CVE-2026-44274 HIGH
Dell Wyse Management Suite (wms) < 2605 - Improper Link Resolution Before File Access ('Link Following')
CVSS 7.8
CVE-2026-55443 MEDIUM
LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders
CVSS 5.1
CVE-2026-56236 MEDIUM
Capgo CLI - Arbitrary File Overwrite via Symlink-Following in Local Credential Operations
CVSS 6.1
CVE-2026-47833 MEDIUM
Cloud Foundry Foundation Bpm-release < 1.4.30 - Improper Link Resolution Before File Access ('Link Following')
CVSS 6.1
CVE-2026-12567 LOW
Black Lantern Security BBOT - Symlink-Following Arbitrary Write via github_workflows Module
CVSS 2.2
CVE-2026-47277 MEDIUM
Runtipi: Unauthenticated arbitrary file read through app-store logo symlinks
CVSS 6.5
CVE-2026-50656 HIGH
Microsoft Defender Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-54230 HIGH
Abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites
CVSS 7.0
CVE-2026-54056 HIGH
Kitty has an arbitrary file overwrite via symlink following in `kitten dnd` remote drop staging
CVSS 7.6
CVE-2026-54055 MEDIUM
Kitty has an Arbitrary File Write via Symlink Race Condition in File Transmission Protocol
CVSS 5.0
CVE-2026-45384 MEDIUM
bit7z: Arbitrary File Overwrite via Symlink Attack on Predictable Temp File During Archive Update
CVSS 6.1
CVE-2026-53476 CRITICAL
Assisted-migration-agent: vddk tarball chained-symlink arbitrary file write
CVSS 9.6
CVE-2026-11853 MEDIUM
Debusine >=0.12.0 <0.14.9 - Arbitrary Symbolic Link Creation via Mergeuploads Task
CVSS 6.5
CVE-2026-11837 HIGH
Ansible-collection-ansible-posix: ansible.posix authorized_key: local privilege escalation via symlink-following chown
CVSS 7.3
Details
Vulnerabilities 1,612
Exploit Likelihood Medium