VulnSea

CWE-59

CVEs classified under CWE-59, newest first.

218 CVEsRSS

CVE-2026-59311Medium· 6.8
1mo ago

A local unprivileged user on the same host can redirect all Zip/UnZip transformer output into a directory of their choosing by pre-creating /tmp/ziptransformer as a symlink before the application starts. Spring Integration 7.1.0 Spring I…

A local unprivileged user on the same host can redirect all Zip/UnZip transformer output into a directory of their choosing by pre-creating /tmp/ziptransformer as a symlink before the application starts. Spring Integration 7.1.0 Spring I…

▾ SunlitEPSS 0.39%via NVD
CVE-2026-61792High· 7.7
1mo ago

Weblate is a web-based continuous localization platform used to manage software translations

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a project administrator can read files outside their repository through the App store metadata download feature, w…

▾ TwilightEPSS 0.59%via NVD
CVE-2026-76845Medium· 6.5
1mo ago

adm-zip 0.5.9 through 0.6.0 follows symbolic links at the extraction destination

adm-zip 0.5.9 through 0.6.0 follows symbolic links at the extraction destination. Utils.sanitize in util/utils.js enforces containment by comparing only the string form of an archive entry name against the resolved extraction root, and U…

▾ Sunlitadm-zip · adm-zipEPSS 0.17%via NVD
CVE-2026-70626Medium· 6.2
1mo ago

NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to read arbitrary files outside the corpus root

NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to read arbitrary files outside the corpus root. The vulnerability exists because path validation is lexical and does no…

▾ Sunlitnltk · nltkEPSS 0.20%via NVD
CVE-2026-62384High· 7.5
1mo ago

NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root

NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path separators i…

▾ Twilightnltk · nltkEPSS 0.65%via NVD
CVE-2026-62383Medium· 5.5
1mo ago

nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely

nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely. Attackers can place a symlink in the corpus root directory and read arbitra…

▾ Sunlitnltk · nltkEPSS 0.18%via NVD
CVE-2026-77815High· 7.5PoC
1mo ago

to_abs_path in scripts/iib/tool.py normalised the requested path with os.path.normpath, which collapses dot segments but does not resolve symbolic links

to_abs_path in scripts/iib/tool.py normalised the requested path with os.path.normpath, which collapses dot segments but does not resolve symbolic links. A symlink placed inside a scanned directory therefore satisfies the containment com…

▾ Midnightzanllp · infinite-image-browsingEPSS 0.51%via NVD
CVE-2026-63125Critical· 9.9
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and `can_create_instances`) can execute arbitrary code …

▾ MidnightEPSS 0.66%via NVD
CVE-2026-71493Medium
1mo ago

Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD

Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, the readFile, pathExists, isDir, and matchPaths template functions in internal/config/template/parser.go use a lexical filepath.Rel …

▾ Sunlitinfracost · github.com/infracost/infracostEPSS 0.54%via NVD
CVE-2026-49114High· 7.1
1mo ago

In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_data location field and opens it for writing without 'O_NOFOLLOW/O_EXCL', after a non-atomic 'os.path.isfile()' check

In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_data location field and opens it for writing without 'O_NOFOLLOW/O_EXCL', after a non-atomic 'os.path.isfile()' check. …

▾ Twilightlinuxfoundation · onnxEPSS 0.16%via NVD
CVE-2026-16989High· 7.1
1mo ago

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper resolution of symbolic links.

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper resolution of symbolic links.

▾ TwilightEPSS 0.13%via NVD
CVE-2026-47187Critical· 9.3
1mo ago

SSHFS is a network filesystem client for connecting to SSH servers

SSHFS is a network filesystem client for connecting to SSH servers. Prior to version 3.7.6, a rogue SFTP server can return absolute symlink targets or relative targets containing parent-directory components that SSHFS passes through FUSE…

▾ MidnightEPSS 0.50%via NVD
CVE-2026-55086Medium· 4.2
1mo ago

Etherpad is a real-time collaborative editor

Etherpad is a real-time collaborative editor. Prior to 3.1.0, src/node/handler/ImportHandler.ts and src/node/handler/ExportHandler.ts derive temporary filenames from Math.random() and place them in os.tmpdir(). On a host with a shared wo…

▾ Sunlitep_etherpad-lite · ep_etherpad-liteEPSS 0.14%via NVD
CVE-2026-47699Medium· 6.4
1mo ago

Confidential Containers Guest Components provides guest tools and components for confidential container workloads

Confidential Containers Guest Components provides guest tools and components for confidential container workloads. From 0.16.0 until 0.20.0, a crafted OCI image layer can make image_rs::stream::unpack::unpack() create a hardlink outside …

▾ SunlitEPSS 0.37%via NVD
CVE-2026-75914High· 7.5
1mo ago

CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading files

CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading files. Attackers can create workspace symlinks pointing to external files with image ext…

▾ Twilightdeepseek-tui · deepseek-tuiEPSS 0.53%via NVD
CVE-2026-17106High· 7.8PoC
1mo ago

github.com/moby/go-archive: moby/go-archive: Arbitrary file write via link following in tar extraction (CVE-2026-17106)

A flaw was found in moby/go-archive. The tar extraction routines in the component do not properly restrict filesystem operations to the intended destination directory. An attacker who controls the contents of an archive can exploit this by…

▾ MidnightRed Hat · Red Hat Edge Manager 1.2EPSS 0.44%via CSAF
CVE-2026-19693High· 8.1
1mo ago

extract-zip: extract-zip: Arbitrary file write via symlink in archive (CVE-2026-19693)

A flaw was found in extract-zip. This vulnerability allows a remote attacker to perform an arbitrary file write outside the intended destination directory. By crafting a malicious zip archive containing a symbolic link (symlink) and a regu…

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.28%via CSAF
CVE-2026-53766Medium· 6.1
1mo ago

chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots

chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots

▾ Sunlitchrome-devtools-mcp · chrome-devtools-mcpEPSS 0.12%via GHSA
CVE-2026-74796Medium· 6.1
1mo ago

OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization

OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious symlink in a trusted working directory to cause tofu init to write provider package content…

▾ Sunlitopentofu · github.com/opentofu/opentofuEPSS 0.34%via NVD
CVE-2026-63426High· 7.1
1mo ago

During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges.

During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges.

▾ Twilightlenovo · dock_managerEPSS 0.16%via NVD
CVE-2026-0291Medium· 4.4
1mo ago

An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low privileged user to delete system files in a limited scope and disable Prisma A…

An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low privileged user to delete system files in a limited scope and disable Prisma A…

▾ Sunlitpaloaltonetworks · prisma_access_agentEPSS 0.11%via NVD
CVE-2026-70460High· 8.1
1mo ago

rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options

rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options. Attackers with…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.54%via NVD
CVE-2026-53796Medium· 6.3
1mo ago

rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the non-daemon receiver's destination directory handling that allows an attacker who can manipulate destination path parent components to…

rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the non-daemon receiver's destination directory handling that allows an attacker who can manipulate destination path parent components to…

▾ SunlitEPSS 0.11%via NVD
CVE-2026-53793High· 7.4
1mo ago

rsync before 3.5.0 contains a path confinement bypass vulnerability that allows remote clients to escape the intended inner-module root confinement by constructing paths that resolve outside the chroot boundary when the module root conta…

rsync before 3.5.0 contains a path confinement bypass vulnerability that allows remote clients to escape the intended inner-module root confinement by constructing paths that resolve outside the chroot boundary when the module root conta…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.49%via NVD
CVE-2026-73613High· 8.2
1mo ago

filebrowser versions before 2.63.19 contain an out-of-scope file deletion vulnerability in the TUS upload cache eviction mechanism that allows authenticated users with only Create permission to delete arbitrary files outside their scope.…

filebrowser versions before 2.63.19 contain an out-of-scope file deletion vulnerability in the TUS upload cache eviction mechanism that allows authenticated users with only Create permission to delete arbitrary files outside their scope.…

▾ TwilightEPSS 0.56%via NVD
CVE-2026-53785High· 7.1
1mo ago

rsync before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to write files outside the intended destination directory tree by crafting relative paths with symlink components in --relative mode

rsync before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to write files outside the intended destination directory tree by crafting relative paths with symlink components in --relative mode. The make_path…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.17%via NVD
CVE-2026-53783High· 8.1
1mo ago

rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to escape enforced directory restrictions by substituting a symlink…

rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to escape enforced directory restrictions by substituting a symlink…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.49%via NVD
CVE-2026-63294Critical· 9.9
1mo ago

A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system

A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly validate and confine the backup.yaml…

▾ Midnightcanonical · lxdEPSS 0.88%via NVD
CVE-2026-72694High· 7.1
1mo ago

A flaw was found in MRTG

A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can exploit a symbolic link (symlink) following vulnerability. By influencing or pre-placing a s…

▾ TwilightRed Hat · mrtgEPSS 0.17%via NVD
CVE-2026-72971Medium· 5.5
1mo ago

Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability

Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.

▾ SunlitMicrosoft · Windows 11 version 26H1EPSS 0.36%via CVEORG
CWE-59 vulnerabilities (CVEs) — page 3 · VulnSea