CWE-61

High likelihood

UNIX Symbolic Link (Symlink) Following

Parent: CWE-59 - Improper Link Resolution Before File Access ('Link Following')

The product, when opening a file or directory, does not sufficiently account for when the file is a symbolic link that resolves to a target outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.

138 vulnerabilities with CWE-61
CVE-2026-54420 HIGH KEV
Litespeed Technologies cPanel Plugin < 2.4.8 - UNIX Symbolic Link (Symlink) Following
CVSS 8.5
CVE-2026-42306 HIGH
Moby: Race condition in docker cp allows bind mount redirection to host path
CVSS 7.2
CVE-2026-5223 MEDIUM
Crates in third party registries can override the cached source of other crates
CVSS 5.3
CVE-2026-8784 MEDIUM
npitre cramfs-tools cramfsck.c change_file_status symlink
CVSS 4.2
CVE-2026-41937 HIGH
Vvveb < 1.0.8.3 Unrestricted File Upload RCE via Plugin Upload
CVSS 7.2
CVE-2026-6475 HIGH
PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice
CVSS 8.8
CVE-2026-7819 HIGH
pgAdmin 4: Symbolic-link path traversal in File Manager allows arbitrary file write
CVSS 8.1
CVE-2026-29203 HIGH
cPanel 11.86.0.0-11.136.0.8 - Authenticated Local Privilege Escalation via Symlink Following
CVSS 8.8
CVE-2026-42275 HIGH
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write
CVSS 8.7
CVE-2026-31893 MEDIUM
Tunnelblick arbitrary file read via symlink following in tunnelblickd
CVSS 5.5
CVE-2026-7832 HIGH
IObit Advanced SystemCare Service ASC.exe symlink
CVSS 7.0
CVE-2026-43570 MEDIUM
OpenClaw 2026.3.22 < 2026.4.5 - Symlink Traversal in Remote Marketplace Repository Path Handling
CVSS 6.5
CVE-2026-7397 MEDIUM
NousResearch hermes-agent file_tools.py _check_sensitive_path symlink
CVSS 4.4
CVE-2026-41326 HIGH
Kata Containers: CopyFile Policy Subversion via Symlinks
CVSS 8.2
CVE-2026-35372 MEDIUM
uutils coreutils ln Security Bypass via Improper Handling of the --no-dereference Flag
CVSS 5.0
CVE-2026-39861 CRITICAL
Claude Code: Sandbox Escape via Symlink Following Allows Arbitrary File Write Outside Workspace
CVSS 10.0
CVE-2026-28684 MEDIUM
python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallback
CVSS 6.6
CVE-2026-40354 LOW
Flatpak xdg-desktop-portal <1.20.4 - Privilege Escalation
CVSS 2.9
CVE-2026-35632 HIGH
OpenClaw < 2026.2.22 - Symlink Traversal via IDENTITY.md appendFile in agents.create/update
CVSS 7.1
CVE-2026-21916 HIGH
Junos OS: A low privileged user can escalate their privileges so that they can login as root
CVSS 7.3
CVE-2026-39860 CRITICAL
Nix sandbox escape: file write via symlink at FOD `.tmp` copy destination
CVSS 9.0
CVE-2026-35525 HIGH
LiquidJS <10.25.3 Symlinked Templates - Root Restriction Bypass
CVSS 7.5
CVE-2026-34078 CRITICAL
Flatpak <1.16.4 sandbox-expose Symlinks - Sandbox Escape
CVE-2026-34447 MEDIUM
ONNX: External Data Symlink Traversal
CVSS 5.5
CVE-2026-34446 MEDIUM
ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load
CVSS 4.7
Details
Vulnerabilities 138
Exploit Likelihood High