CWE-59
CVEs classified under CWE-59, newest first.
218 CVEsRSS
CVE-2026-70348Medium· 5.5Windows Management Services Denial of Service Vulnerability
Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.
CVE-2026-62812High· 7.8Windows DHCP Server Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
CVE-2026-62807High· 7.8Windows DHCP Server Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
CVE-2026-62803High· 7.8Windows DHCP Server Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
CVE-2026-62776High· 7.8Windows DHCP Server Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
CVE-2026-62761High· 7.8Windows DHCP Server Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
CVE-2026-62832High· 7.8Windows User Profile Service Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.
CVE-2026-65680Medium· 6.7Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.
CVE-2026-61358High· 7.8Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.
Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.
CVE-2026-70622Medium· 6.5tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function that allows attackers to read files outside the intended source root directory by planting symlinks in an attacker-con…
tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function that allows attackers to read files outside the intended source root directory by planting symlinks in an attacker-con…
CVE-2026-71964Medium· 6.5CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file manager component that allows authenticated attackers to read sensitive system files by uploading a crafted ZIP archive containing symbo…
CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file manager component that allows authenticated attackers to read sensitive system files by uploading a crafted ZIP archive containing symbo…
CVE-2026-63622High· 7.8A flaw was found in libvirt
A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within the `sw…
CVE-2026-71556High· 7.1go-git is an extensible git implementation library written in pure Go
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resoluti…
CVE-2026-71476HighNx is a monorepo solution for TypeScript and polyglot codebases
Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx self-hosted HTTP remote cache extracts downloaded cache artifacts without constraining where files are written. A malici…
CVE-2026-70427Medium· 4.3Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of `.tar` and `.tar.gz` archives, allowing attackers able to control agent processes to provide c…
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of `.tar` and `.tar.gz` archives, allowing attackers able to control agent processes to provide c…
CVE-2026-12410High· 7.8Link following vulnerability in the Uninstaller component in CCleaner prior to 7.10.1464 on Windows allows a local, low-privileged attacker to escalate privileges to SYSTEM via a symlink/junction created during application uninstallation…
Link following vulnerability in the Uninstaller component in CCleaner prior to 7.10.1464 on Windows allows a local, low-privileged attacker to escalate privileges to SYSTEM via a symlink/junction created during application uninstallation…
CVE-2026-20310Critical· 9.1As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that …
CVE-2026-54572High· 7.5rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote
rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote
CVE-2026-18508Medium· 4.4A flaw was found in GNU tar
A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted arch…
CVE-2026-54706Medium· 4.8OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbolic links in cli/onionshare_cli/web/sen…
GHSA-6xx4-9wp6-65p7Medium· 6.5skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source
skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source
CVE-2026-17459Medium· 4.3A vulnerability was determined in perwendel spark up to 2.9.4
A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.externalLocation of the file src/main/java/spark/resource/ExternalResourceHandler.jav of the component SparkJava. Executin…
CVE-2026-55607HighClaude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
GHSA-56m6-8q75-f2rwMedium· 4.7ImageMagick: Policy Bypass due to an incomplete fix of CVE-2026-49219
ImageMagick: Policy Bypass due to an incomplete fix of CVE-2026-49219
GHSA-v3j6-27vc-7pw2Low· 3.3ImageMagick: Policy Bypass in APNG encoder and delegates due to a missing check
ImageMagick: Policy Bypass in APNG encoder and delegates due to a missing check
GHSA-vghg-5jrg-2398Low· 3.3ImageMagick: Policy Bypass in script operation due to missing checks
ImageMagick: Policy Bypass in script operation due to missing checks
CVE-2026-55667High· 8.2File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup
File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup
CVE-2026-55668Medium· 6.3File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope
File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope
CVE-2026-16130Medium· 4.4A vulnerability was identified in nearai ironclaw up to 0.29.1
A vulnerability was identified in nearai ironclaw up to 0.29.1. The affected element is the function validate_path of the file src/tools/builtin/path_utils.rs of the component write_file. The manipulation leads to link following. Local a…
CVE-2026-16077Medium· 5.3A vulnerability was found in AstrBotDevs AstrBot up to 4.25.5
A vulnerability was found in AstrBotDevs AstrBot up to 4.25.5. Impacted is the function _normalize_rw_path of the file astrbot/core/tools/computer_tools/fs.py of the component Filesystem Computer-Use Tool. Performing a manipulation resul…