VulnSea

CWE-59

CVEs classified under CWE-59, newest first.

219 CVEsRSS

CVE-2026-35025High· 8.1
3mo ago

ProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass vulnerability that allows authenticated FTP users to circumvent Directory ACL restrictions by prefixing paths with /proc/self/root in the RNFR command handler

ProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass vulnerability that allows authenticated FTP users to circumvent Directory ACL restrictions by prefixing paths with /proc/self/root in the RNFR command handler. Attack…

▾ Twilightproftpd · proftpdEPSS 0.51%via NVD
CVE-2026-56692Medium· 5.5
3mo ago

NanoClaw before 2.1.17 contains a symlink following vulnerability in forwardAttachedFiles that allows container-controlled agents to exfiltrate host-readable files

NanoClaw before 2.1.17 contains a symlink following vulnerability in forwardAttachedFiles that allows container-controlled agents to exfiltrate host-readable files. The host validates attachment filenames using only isSafeAttachmentName …

▾ Sunlitnanocoai · nanoclawEPSS 0.17%via NVD
CVE-2026-11940High· 7.3
3mo ago

tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself.  The extraction fallback validated the symlink at it's…

tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself.  The extraction fallback validated the symlink at it's…

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.75%via NVD
CVE-2026-52811Critical
3mo ago

Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym

Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym

▾ Midnightgogs · gogs.io/gogsEPSS 0.47%via GHSA
GHSA-74p7-6h78-gw8pHigh
3mo ago

skillctl: argument injection, path traversal in --dest, FIFO/device DoS, hardlink exfiltration, and commit-trailer forgery

skillctl: argument injection, path traversal in --dest, FIFO/device DoS, hardlink exfiltration, and commit-trailer forgery

▾ Twilightskillctl · skillctlvia GHSA
CVE-2026-54352Critical· 9.6
3mo ago

Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload

Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload

▾ Midnightbudibase · @budibase/serverEPSS 0.49%via GHSA
GHSA-c3wq-j5vh-68rcMedium
3mo ago

Hugo: Symlink confinement bypass in os.ReadFile

Hugo: Symlink confinement bypass in os.ReadFile

▾ Sunlitgohugoio · github.com/gohugoio/hugovia GHSA
CVE-2026-23879High· 8.0
3mo ago

py7zr: Arbitrary File Write Vulnerability

py7zr: Arbitrary File Write Vulnerability

▾ Twilightpy7zr · py7zrEPSS 0.57%via GHSA
GHSA-6x2m-p4xp-wg22Medium· 5.5
3mo ago

Network-AI: EnvironmentManager.backup() follows symlinked directories and copies files outside the environment root into backups

Network-AI: EnvironmentManager.backup() follows symlinked directories and copies files outside the environment root into backups

▾ Sunlitnetwork-ai · network-aivia GHSA
GHSA-4xgf-cpjx-pc3jMedium· 5.3
3mo ago

pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size

pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size

▾ Sunlitpydantic-settings · pydantic-settingsvia GHSA
CVE-2026-55686Medium· 5.3
3mo ago

Podman: WORKDIR symlink traversal vulnerability

Podman: WORKDIR symlink traversal vulnerability

▾ Sunlitcontainers · github.com/containers/podman/v5EPSS 0.40%via GHSA
CVE-2026-12567Low· 2.2
3mo ago

BBOT: Symlink-Following Arbitrary Write via github_workflows Module

BBOT: Symlink-Following Arbitrary Write via github_workflows Module

▾ Sunlitbbot · bbotEPSS 0.09%via GHSA
GHSA-2jq4-q6vv-4cp3Critical· 9.6
3mo ago

Crawl4AI: Arbitrary file write (path traversal) in crawler downloads can lead to RCE

Crawl4AI: Arbitrary file write (path traversal) in crawler downloads can lead to RCE

▾ Midnightcrawl4ai · crawl4aivia GHSA
CVE-2026-53765Medium· 6.1
3mo ago

Chrome DevTools for agents: daemon.pid write follows symlinks in /tmp fallback runtime directory

Chrome DevTools for agents: daemon.pid write follows symlinks in /tmp fallback runtime directory

▾ Sunlitchrome-devtools-mcp · chrome-devtools-mcpEPSS 0.10%via GHSA
CVE-2026-50656High· 7.8PoC
3mo ago

Microsoft Defender Elevation of Privilege Vulnerability

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".

▾ MidnightMicrosoft · Microsoft Malware Protection EngineEPSS 0.37%via CVEORG
GHSA-gr75-jv2w-4656Medium· 5.1
3mo ago

LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders

LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders

▾ Sunlitlangchain · langchainvia GHSA
CVE-2026-50135Medium
3mo ago

Hugo: Symlink confinement bypass in resources.Get

Hugo: Symlink confinement bypass in resources.Get

▾ Sunlitgohugoio · github.com/gohugoio/hugoEPSS 0.41%via GHSA
GHSA-7cx2-g3h9-382pHigh· 8.1
3mo ago

Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server

Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server

▾ Twilightcrawl4ai · crawl4aivia GHSA
CVE-2026-54230High· 7.0
3mo ago

A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport

A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink,…

▾ Twilightredhat · automatic_bug_reporting_toolEPSS 0.18%via NVD
CVE-2026-54094Medium· 6.8
3mo ago

File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope

File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope

▾ Sunlitfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.50%via GHSA
CVE-2026-11837High· 7.3PoC
3mo ago

A local privilege escalation vulnerability was found in the ansible.posix authorized_key module

A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() instead of os.lchown() and opens files without O_NOFOLLOW when managing SSH authorized keys.…

▾ MidnightRed Hat · rhc-worker-playbookEPSS 0.16%via NVD
CVE-2026-45586High· 7.8
3mo ago

Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability

Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.37%via CVEORG
CVE-2026-50511High· 7.8
3mo ago

Microsoft PC Manager Elevation of Privilege Vulnerability

Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Microsoft PC ManagerEPSS 0.37%via CVEORG
CVE-2026-42989High· 7.8
3mo ago

Winlogon Elevation of Privilege Vulnerability

Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.37%via CVEORG
CVE-2026-41841Medium· 5.9
3mo ago

Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3…

Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3…

▾ Sunlitvmware · spring_frameworkEPSS 0.34%via NVD
CVE-2026-45491Medium· 6.2
3mo ago

.NET Tampering Vulnerability

Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally.

▾ SunlitMicrosoft · .NET 10.0EPSS 0.37%via CVEORG
CVE-2026-42795Medium· 5.1PoC
3mo ago

Symlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in the generated package tarball. The file collection helpers (gleam_files, native_files, private_files) in compiler-cli/…

Symlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in the generated package tarball. The file collection helpers (gleam_files, native_files, private_files) in compiler-cli/…

▾ TwilightGleam · gleamEPSS 0.17%via NVD
CVE-2026-9804High· 7.7
4mo ago

A flaw was found in KubeVirt's virt-exportserver component

A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an ex…

▾ TwilightRed Hat · container-native-virtualization/virt-exportserver-rhel9EPSS 0.72%via NVD
CVE-2026-7374Critical· 9.9
4mo ago

A flaw was found in KubeVirt's virt-handler component

A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine consol…

▾ MidnightRed Hat · kubevirtEPSS 0.83%via NVD
CVE-2026-42834High· 7.8
4mo ago

Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

▾ Twilightmicrosoft · windows_admin_centerEPSS 0.37%via NVD
CWE-59 vulnerabilities (CVEs) — page 6 · VulnSea