CWE-61
High likelihoodUNIX Symbolic Link (Symlink) Following
The product, when opening a file or directory, does not sufficiently account for when the file is a symbolic link that resolves to a target outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.
158 vulnerabilities with CWE-61
CVE-2026-54574
HIGH
`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive
CVSS 8.2
CVE-2026-56748
HIGH
Authenticated RCE via Symlink Following in Cribl Stream Pack Git Import
CVSS 8.8
CVE-2026-17459
MEDIUM
perwendel spark SparkJava ExternalResourceHandler.jav staticFiles.externalLocation symlink
CVSS 4.3
CVE-2026-65010
MEDIUM
Datasets Symlink-following Arbitrary File Write via Extractor.extract()
CVSS 6.6
CVE-2026-12080
HIGH
Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys
CVSS 7.3
CVE-2026-59674
HIGH
LPE from suricata user to root due to chown in %post in suricata packaging
CVE-2026-39822
HIGH
Root escape via symlink plus trailing slash in os
CVSS 7.8
CVE-2026-14699
LOW
zcaceres markdownify-mcp Markdownify.ts assertPathAllowed symlink
CVSS 3.3
CVE-2026-53489
MEDIUM
containerd: Arbitrary host CRI log file read via symlink following in CRI checkpoint restore
CVSS 6.5
CVE-2026-41579
LOW
runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations
CVSS 3.3
CVE-2026-13748
MEDIUM
Snowflake CLI Arbitrary Local File Read and Exfiltration Through Improper File Path Restriction
CVSS 6.3
CVE-2026-56876
HIGH
extract-zip unvalidated symlink path traversal
CVSS 8.1
CVE-2026-55686
MEDIUM
Podman: WORKDIR symlink traversal vulnerability
CVSS 5.3
CVE-2026-13218
MEDIUM
Kubevirt: kubevirt: symlink following in writetocachedfile allows host file overwrite from virt-launcher
CVSS 4.2
CVE-2026-52811
CRITICAL
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym
CVE-2026-13201
HIGH
OpenShift Virtualization KubeVirt safepath - Host File Metadata Modification
CVSS 7.3
CVE-2026-55447
CRITICAL
Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
CVSS 9.6
CVE-2026-12958
HIGH
Arbitrary file write in Language Servers for AWS
CVSS 7.8
CVE-2026-56815
HIGH
Rasta-mouse Pwnlift - UNIX Symbolic Link (Symlink) Following
CVSS 7.4
CVE-2026-49248
HIGH
OneDev <= 15.0.6 - Authenticated Arbitrary File Overwrite via TarUtils.untar
CVE-2026-54420
HIGH
KEV
Litespeed Technologies cPanel Plugin < 2.4.8 - UNIX Symbolic Link (Symlink) Following
CVSS 8.5
CVE-2026-42306
HIGH
Moby: Race condition in docker cp allows bind mount redirection to host path
CVSS 7.2
CVE-2026-5223
MEDIUM
Crates in third party registries can override the cached source of other crates
CVSS 5.3
CVE-2026-8784
MEDIUM
npitre cramfs-tools cramfsck.c change_file_status symlink
CVSS 4.2
CVE-2026-41937
HIGH
Vvveb < 1.0.8.3 Unrestricted File Upload RCE via Plugin Upload
CVSS 7.2
Details
Vulnerabilities
158
Exploit Likelihood
High