VulnSea

CWE-61

CVEs classified under CWE-61, newest first.

29 CVEsRSS

CVE-2026-91202Medium· 6.1
4d ago

A flaw was found in cockpit-files

A flaw was found in cockpit-files. A low-privileged local user can exploit this vulnerability by crafting a directory containing a symbolic link (symlink) and then using the privileged "Paste as owner" function. This allows for arbitrary…

SunlitRed Hat · cockpit-filesEPSS 0.12%via NVD
CVE-2026-91099Critical· 9.8⚖ disputed
6d ago

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, inf…

Midnighthp · linux_imaging_and_printingEPSS 0.33%via NVD
CVE-2026-90616High· 7.4
1w ago

In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbitrary code execution on the host, a different vulnerability than CVE-2026-76925

In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbitrary code execution on the host, a different vulnerability than CVE-2026-76925. Flatpak c…

TwilightFlatpak · FlatpakEPSS 0.17%via NVD
CVE-2026-77159Medium· 5.5PoC
1w ago

A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function

A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile without checking for symbolic links. A local attacker with access to the swtpm account can…

TwilightRed Hat · libvirtEPSS 0.16%via NVD
CVE-2026-57825Medium· 5.7
1w ago

In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.

In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.

SunlitOCaml · opamEPSS 0.31%via NVD
CVE-2026-81727High· 7.1
3w ago

nltk: NLTK: Filesystem containment bypass allows local file overwrite (CVE-2026-81727)

A flaw was found in NLTK. This vulnerability, a filesystem containment bypass, allows a local attacker with write access to a shared downloader directory to create special links (hardlinks) that point to files outside the intended installa…

TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.14%via CSAF
CVE-2026-63125Critical· 9.9
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and `can_create_instances`) can execute arbitrary code …

MidnightEPSS 0.50%via NVD
CVE-2026-64846Low· 2.8
1mo ago

Nix is a package manager for Linux and other Unix systems

Nix is a package manager for Linux and other Unix systems. Prior to 2.35.0, a malicious derivation executed with the recursive-nix experimental feature can exploit a time-of-check/time-of-use race involving final symlink handling in the …

SunlitEPSS 0.09%via NVD
CVE-2026-47766None
1mo ago

crun is an open source OCI Container Runtime fully written in C

crun is an open source OCI Container Runtime fully written in C. Prior to version 1.28, crun's default device setup opens the container rootfs `/dev` directory without `O_NOFOLLOW`. If an OCI bundle contains `rootfs/dev` as a symlink and…

SunlitEPSS 0.16%via NVD
CVE-2026-62992Medium
1mo ago

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 5.8.2 (and 4.5.7 on the 4.x line), Security::_checkDir() does not fully resolve symbolic links before validating…

Sunlitsmarty · smarty/smartyEPSS 0.36%via NVD
CVE-2026-47763Medium
1mo ago

pdm is a Python package and dependency manager supporting the latest PEP standards

pdm is a Python package and dependency manager supporting the latest PEP standards. In versions prior to 2.27.0, pdm writes several project-local state or configuration files without symlink protection. If a malicious repository places t…

Sunlitpdm · pdmEPSS 0.22%via NVD
CVE-2026-54574High· 8.2
1mo ago

`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive

`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive

Twilightproot-distro · proot-distroEPSS 0.14%via GHSA
GHSA-6xx4-9wp6-65p7Medium· 6.5
1mo ago

skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source

skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source

Sunlitskilo · skilovia GHSA
CVE-2026-17459Medium· 4.3
1mo ago

A vulnerability was determined in perwendel spark up to 2.9.4

A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.externalLocation of the file src/main/java/spark/resource/ExternalResourceHandler.jav of the component SparkJava. Executin…

SunlitEPSS 0.32%via NVD
CVE-2026-12080High· 7.3
2mo ago

A flaw was found in the QEMU Guest Agent (qga)

A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-add-authorized-keys command handler by manipulating symbolic links. This can occur either through a deterministic dire…

TwilightEPSS 0.18%via NVD
CVE-2026-39822High· 7.8
2mo ago

On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /

On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will o…

Twilightgolang · goEPSS 0.23%via NVD
CVE-2026-53489Medium· 6.5
2mo ago

github.com/containerd/containerd: containerd: Arbitrary host file read via symlink following in CRI checkpoint restore (CVE-2026-53489)

A flaw was found in containerd, an open-source container runtime. The Container Runtime Interface (CRI) plugin incorrectly restores container logs from a checkpoint image. This vulnerability, categorized as a Path Traversal (CWE-61), allow…

SunlitRed Hat · Red Hat Openshift Data Foundation 4.20EPSS 0.17%via CSAF
CVE-2026-5223Medium
2mo ago

Cargo crates in third party registries can override the cached source of other crates

Cargo crates in third party registries can override the cached source of other crates

Sunlitcargo · cargoEPSS 0.29%via GHSA
CVE-2026-13201High· 7.3
3mo ago

A flaw was found in KubeVirt's safepath package used by virt-handler

A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to obtain a file descriptor to a path leaf, but downstream operations resolve the path via /proc/self/fd/N using lin…

Twilightkubevirt · kubevirtEPSS 0.22%via NVD
CVE-2026-56815High· 7.4
3mo ago

pwnlift before d7a9544, in a privileged deployment, contains a symlink following vulnerability in the upload handler in Components/Pages/Home.razor.

pwnlift before d7a9544, in a privileged deployment, contains a symlink following vulnerability in the upload handler in Components/Pages/Home.razor.

TwilightEPSS 0.17%via NVD
CVE-2026-52811Critical
3mo ago

Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym

Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym

Midnightgogs · gogs.io/gogsEPSS 0.47%via GHSA
GHSA-wcmj-x466-56mmMedium· 6.1
3mo ago

OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree

OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree

Sunlitopentofu · github.com/opentofu/opentofuvia GHSA
CVE-2026-41579Medium· 3.3
3mo ago

runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations

runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations

Sunlitopencontainers · github.com/opencontainers/runcEPSS 0.19%via GHSA
CVE-2026-55447Critical· 9.6
3mo ago

Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit

Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit

Midnightlangflow · langflowEPSS 0.66%via GHSA
GHSA-wvrh-2f4m-924vMedium· 5.5
3mo ago

ChatterBot: Symlink-Following Arbitrary Write via UbuntuCorpusTrainer

ChatterBot: Symlink-Following Arbitrary Write via UbuntuCorpusTrainer

SunlitChatterBot · ChatterBotvia GHSA
CVE-2026-12565Medium· 5.3
3mo ago

BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284

BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284

Sunlitbbot · bbotEPSS 0.21%via GHSA
CVE-2026-41326High· 8.2
5mo ago

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. From v3.4.0 to v3.28.0, an oversight in the CopyFile policy (and perhaps the CopyFile han…

Twilightkatacontainers · confidential_containersEPSS 0.35%via NVD
CVE-2026-34078Critical· 10.0
5mo ago

Flatpak is a Linux application sandboxing and distribution framework

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts th…

Midnightflatpak · flatpakEPSS 1.7%via NVD
CVE-2025-9566High· 8.1
1y ago

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In…

TwilightRed Hat · podmanEPSS 1.1%via NVD
CWE-61 vulnerabilities (CVEs) · VulnSea