CWE-59
AllowedImproper Link Resolution Before File Access ('Link Following')
Abstraction: Base · Status: Draft
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
2320 vulnerabilities reference this CWE, most recent first.
GHSA-VRH7-99JH-3FMM
Vulnerability from github – Published: 2022-05-02 06:10 – Updated: 2024-02-06 22:38Puppet 0.24.x before 0.24.9 and 0.25.x before 0.25.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/daemonout, (2) /tmp/puppetdoc.txt, (3) /tmp/puppetdoc.tex, or (4) /tmp/puppetdoc.aux temporary file.
{
"affected": [
{
"package": {
"ecosystem": "RubyGems",
"name": "puppet"
},
"ranges": [
{
"events": [
{
"introduced": "0.24.0"
},
{
"fixed": "0.24.9"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "RubyGems",
"name": "puppet"
},
"ranges": [
{
"events": [
{
"introduced": "0.25.0"
},
{
"fixed": "0.25.2"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2010-0156"
],
"database_specific": {
"cwe_ids": [
"CWE-59"
],
"github_reviewed": true,
"github_reviewed_at": "2024-02-06T22:38:26Z",
"nvd_published_at": "2010-03-03T19:30:00Z",
"severity": "LOW"
},
"details": "Puppet 0.24.x before 0.24.9 and 0.25.x before 0.25.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/daemonout, (2) /tmp/puppetdoc.txt, (3) /tmp/puppetdoc.tex, or (4) /tmp/puppetdoc.aux temporary file.",
"id": "GHSA-vrh7-99jh-3fmm",
"modified": "2024-02-06T22:38:26Z",
"published": "2022-05-02T06:10:33Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2010-0156"
},
{
"type": "WEB",
"url": "https://github.com/puppetlabs/puppet/commit/0aae57f91dc69b22fb674f8de3a13c22edd07128"
},
{
"type": "WEB",
"url": "https://github.com/puppetlabs/puppet/commit/6111ba80f2c6f6d1541af971f565119e6e03d77d"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=502881"
},
{
"type": "PACKAGE",
"url": "https://github.com/puppetlabs/puppet"
},
{
"type": "WEB",
"url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/puppet/CVE-2010-0156.yml"
},
{
"type": "WEB",
"url": "https://puppet.com/security/cve/cve-2010-0156"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20100316113904/http://secunia.com/advisories/38766"
},
{
"type": "WEB",
"url": "http://groups.google.com/group/puppet-announce/browse_thread/thread/4401823f6cbf6087"
},
{
"type": "WEB",
"url": "http://groups.google.com/group/puppet-announce/browse_thread/thread/73cd1b2896d986c2"
},
{
"type": "WEB",
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036083.html"
},
{
"type": "WEB",
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036166.html"
},
{
"type": "WEB",
"url": "http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html"
}
],
"schema_version": "1.4.0",
"severity": [],
"summary": "Puppet arbitrary files overwrite via a symlink attack"
}
GHSA-VRPP-JRQV-4GJ2
Vulnerability from github – Published: 2024-03-26 15:30 – Updated: 2024-03-26 15:30An arbitrary file deletion in ZSATrayManager where it protects the temporary encrypted ZApp issue reporting file from the unprivileged end user access and modification. Fixed version: Win ZApp 4.3.0 and later.
{
"affected": [],
"aliases": [
"CVE-2023-41969"
],
"database_specific": {
"cwe_ids": [
"CWE-59",
"CWE-61"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-26T15:15:48Z",
"severity": "HIGH"
},
"details": "\nAn arbitrary file deletion in ZSATrayManager where it protects the temporary encrypted ZApp issue reporting file from the unprivileged end user access and modification. Fixed version: Win ZApp 4.3.0 and later.\n\n",
"id": "GHSA-vrpp-jrqv-4gj2",
"modified": "2024-03-26T15:30:50Z",
"published": "2024-03-26T15:30:50Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41969"
},
{
"type": "WEB",
"url": "https://help.zscaler.com/client-connector/client-connector-app-release-summary-2023"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L",
"type": "CVSS_V3"
}
]
}
GHSA-VRVQ-8HXG-GC46
Vulnerability from github – Published: 2022-05-17 02:17 – Updated: 2022-05-17 02:17The SmartPoster implementation on the Nokia 6131 Near Field Communication (NFC) phone with 05.12 firmware does not properly display the URI record when the Title record contains a certain combination of space, CR (aka \r), and . (dot) characters, which allows remote attackers to trick a user into loading an arbitrary URI via a crafted NDEF tag, as demonstrated by (1) an http: URI for a malicious web site, (2) a tel: URI for a premium-rate telephone number, and (3) an sms: URI that triggers purchase of a ringtone.
{
"affected": [],
"aliases": [
"CVE-2008-5825"
],
"database_specific": {
"cwe_ids": [
"CWE-59"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2009-01-02T19:30:00Z",
"severity": "LOW"
},
"details": "The SmartPoster implementation on the Nokia 6131 Near Field Communication (NFC) phone with 05.12 firmware does not properly display the URI record when the Title record contains a certain combination of space, CR (aka \\r), and . (dot) characters, which allows remote attackers to trick a user into loading an arbitrary URI via a crafted NDEF tag, as demonstrated by (1) an http: URI for a malicious web site, (2) a tel: URI for a premium-rate telephone number, and (3) an sms: URI that triggers purchase of a ringtone.",
"id": "GHSA-vrvq-8hxg-gc46",
"modified": "2022-05-17T02:17:04Z",
"published": "2022-05-17T02:17:04Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2008-5825"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44527"
},
{
"type": "WEB",
"url": "http://archives.neohapsis.com/archives/bugtraq/2008-08/0186.html"
},
{
"type": "WEB",
"url": "http://archives.neohapsis.com/archives/fulldisclosure/2008-08/0344.html"
},
{
"type": "WEB",
"url": "http://events.ccc.de/congress/2008/Fahrplan/attachments/1109_collin_mulliner_eusecwest08_attacking_nfc_phones_slim.pdf"
},
{
"type": "WEB",
"url": "http://events.ccc.de/congress/2008/Fahrplan/events/2639.en.html"
},
{
"type": "WEB",
"url": "http://www.mulliner.org/nfc/feed/collin_mulliner_25c3_attacking_nfc_phones.pdf"
},
{
"type": "WEB",
"url": "http://www.mulliner.org/nfc/feed/collin_mulliner_eusecwest08_attacking_nfc_phones.pdf"
},
{
"type": "WEB",
"url": "http://www.mulliner.org/security/advisories/nokia6131nfc_uri_spoofing_and_dos_advisory.txt"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/30716"
}
],
"schema_version": "1.4.0",
"severity": []
}
GHSA-VVQG-CGQR-C8GC
Vulnerability from github – Published: 2025-06-10 18:32 – Updated: 2025-06-10 18:32Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally.
{
"affected": [],
"aliases": [
"CVE-2025-33075"
],
"database_specific": {
"cwe_ids": [
"CWE-59"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-10T17:23:08Z",
"severity": "HIGH"
},
"details": "Improper link resolution before file access (\u0027link following\u0027) in Windows Installer allows an authorized attacker to elevate privileges locally.",
"id": "GHSA-vvqg-cgqr-c8gc",
"modified": "2025-06-10T18:32:29Z",
"published": "2025-06-10T18:32:29Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33075"
},
{
"type": "WEB",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33075"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-VVXG-893H-9Q6M
Vulnerability from github – Published: 2022-05-01 23:48 – Updated: 2022-05-01 23:48uulib/uunconc.c in UUDeview 0.5.20, as used in nzbget before 0.3.0 and possibly other products, allows local users to overwrite arbitrary files via a symlink attack on a temporary filename generated by the tempnam function. NOTE: this may be a CVE-2004-2265 regression.
{
"affected": [],
"aliases": [
"CVE-2008-2266"
],
"database_specific": {
"cwe_ids": [
"CWE-59"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2008-05-16T12:54:00Z",
"severity": "MODERATE"
},
"details": "uulib/uunconc.c in UUDeview 0.5.20, as used in nzbget before 0.3.0 and possibly other products, allows local users to overwrite arbitrary files via a symlink attack on a temporary filename generated by the tempnam function. NOTE: this may be a CVE-2004-2265 regression.",
"id": "GHSA-vvxg-893h-9q6m",
"modified": "2022-05-01T23:48:19Z",
"published": "2022-05-01T23:48:19Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2008-2266"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/42407"
},
{
"type": "WEB",
"url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=480972"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/30171"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/31420"
},
{
"type": "WEB",
"url": "http://security.gentoo.org/glsa/glsa-200808-11.xml"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2008/05/14/10"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2008/05/30/1"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/29211"
}
],
"schema_version": "1.4.0",
"severity": []
}
GHSA-VW3J-PCRQ-5HXC
Vulnerability from github – Published: 2022-05-17 02:02 – Updated: 2022-05-17 02:02dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via a symlink attack on unspecified files in the .pc directory.
{
"affected": [],
"aliases": [
"CVE-2011-0402"
],
"database_specific": {
"cwe_ids": [
"CWE-59"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2011-01-11T03:00:00Z",
"severity": "MODERATE"
},
"details": "dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via a symlink attack on unspecified files in the .pc directory.",
"id": "GHSA-vw3j-pcrq-5hxc",
"modified": "2022-05-17T02:02:39Z",
"published": "2022-05-17T02:02:39Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2011-0402"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/64614"
},
{
"type": "WEB",
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053306.html"
},
{
"type": "WEB",
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053311.html"
},
{
"type": "WEB",
"url": "http://osvdb.org/70367"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/42826"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/42831"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/43054"
},
{
"type": "WEB",
"url": "http://www.debian.org/security/2011/dsa-2142"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/45703"
},
{
"type": "WEB",
"url": "http://www.ubuntu.com/usn/USN-1038-1"
},
{
"type": "WEB",
"url": "http://www.vupen.com/english/advisories/2011/0040"
},
{
"type": "WEB",
"url": "http://www.vupen.com/english/advisories/2011/0044"
},
{
"type": "WEB",
"url": "http://www.vupen.com/english/advisories/2011/0196"
}
],
"schema_version": "1.4.0",
"severity": []
}
GHSA-VWC7-R8MQ-G2X9
Vulnerability from github – Published: 2026-08-24 15:31 – Updated: 2026-09-08 21:20adm-zip 0.5.9 through 0.6.0 follows symbolic links at the extraction destination. Utils.sanitize in util/utils.js enforces containment by comparing only the string form of an archive entry name against the resolved extraction root, and Utils.writeFileTo opens the computed destination with fs.openSync(path, "w", 0o666), which resolves symbolic links and carries neither O_NOFOLLOW nor a pre-write fs.lstatSync check. When a path component at the destination already exists as a symbolic link pointing outside the extraction root, extractAllTo, extractAllToAsync and extractEntryTo write the entry contents through that link and then chmod its target, placing attacker-controlled content in a file outside the root without any traversal sequence appearing in the archive. Reaching the write requires overwrite to be enabled, because the preceding fs.existsSync check also resolves the link and otherwise declines. An attacker able to create a symbolic link inside a shared, reused or predictable extraction directory, such as a temporary directory or a continuous integration workspace, can overwrite any file the extracting process is permitted to write.
{
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "adm-zip"
},
"ranges": [
{
"events": [
{
"introduced": "0.5.9"
},
{
"last_affected": "0.6.0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2026-76845"
],
"database_specific": {
"cwe_ids": [
"CWE-59"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-08T21:20:41Z",
"nvd_published_at": "2026-08-24T14:17:02Z",
"severity": "MODERATE"
},
"details": "adm-zip 0.5.9 through 0.6.0 follows symbolic links at the extraction destination. Utils.sanitize in util/utils.js enforces containment by comparing only the string form of an archive entry name against the resolved extraction root, and Utils.writeFileTo opens the computed destination with fs.openSync(path, \"w\", 0o666), which resolves symbolic links and carries neither O_NOFOLLOW nor a pre-write fs.lstatSync check. When a path component at the destination already exists as a symbolic link pointing outside the extraction root, extractAllTo, extractAllToAsync and extractEntryTo write the entry contents through that link and then chmod its target, placing attacker-controlled content in a file outside the root without any traversal sequence appearing in the archive. Reaching the write requires overwrite to be enabled, because the preceding fs.existsSync check also resolves the link and otherwise declines. An attacker able to create a symbolic link inside a shared, reused or predictable extraction directory, such as a temporary directory or a continuous integration workspace, can overwrite any file the extracting process is permitted to write.",
"id": "GHSA-vwc7-r8mq-g2x9",
"modified": "2026-09-08T21:20:41Z",
"published": "2026-08-24T15:31:51Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76845"
},
{
"type": "WEB",
"url": "https://github.com/cthackers/adm-zip/issues/574"
},
{
"type": "WEB",
"url": "https://github.com/cthackers/adm-zip/pull/575"
},
{
"type": "PACKAGE",
"url": "https://github.com/cthackers/adm-zip"
},
{
"type": "WEB",
"url": "https://github.com/cthackers/adm-zip/blob/v0.6.0/util/utils.js"
},
{
"type": "WEB",
"url": "https://www.vulncheck.com/advisories/adm-zip-through-arbitrary-file-overwrite-via-symlink-following-on-extraction"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
"type": "CVSS_V4"
}
],
"summary": "adm-zip extraction follows destination symlinks, allowing arbitrary file overwrite"
}
GHSA-VWP3-7R9H-7H5C
Vulnerability from github – Published: 2022-05-17 04:50 – Updated: 2022-05-17 04:50LightDM before 1.0.6 allows local users to change ownership of arbitrary files via a symlink attack on ~/.Xauthority.
{
"affected": [],
"aliases": [
"CVE-2011-4105"
],
"database_specific": {
"cwe_ids": [
"CWE-59"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2012-02-17T23:55:00Z",
"severity": "LOW"
},
"details": "LightDM before 1.0.6 allows local users to change ownership of arbitrary files via a symlink attack on ~/.Xauthority.",
"id": "GHSA-vwp3-7r9h-7h5c",
"modified": "2022-05-17T04:50:16Z",
"published": "2022-05-17T04:50:16Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2011-4105"
},
{
"type": "WEB",
"url": "http://lists.freedesktop.org/archives/lightdm/2011-November/000178.html"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2011/11/02/10"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2011/11/02/6"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2011/11/02/9"
},
{
"type": "WEB",
"url": "http://www.ubuntu.com/usn/USN-1262-1"
}
],
"schema_version": "1.4.0",
"severity": []
}
GHSA-VWVH-64P3-W4GH
Vulnerability from github – Published: 2022-09-01 00:00 – Updated: 2022-09-03 00:00Measuresoft ScadaPro Server and Client (All Versions) do not properly resolve links before file access; this could allow privilege escalation..
{
"affected": [],
"aliases": [
"CVE-2022-2897"
],
"database_specific": {
"cwe_ids": [
"CWE-59"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-08-31T21:15:00Z",
"severity": "HIGH"
},
"details": "Measuresoft ScadaPro Server and Client (All Versions) do not properly resolve links before file access; this could allow privilege escalation..",
"id": "GHSA-vwvh-64p3-w4gh",
"modified": "2022-09-03T00:00:16Z",
"published": "2022-09-01T00:00:16Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2897"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-235-06"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-VWXC-3CFR-37JQ
Vulnerability from github – Published: 2022-05-04 00:27 – Updated: 2024-11-22 20:16libs/updater.py in GoLismero 0.6.3, and other versions before Git revision 2b3bb43d6867, as used in backtrack and possibly other products, allows local users to overwrite arbitrary files via a symlink attack on GoLismero-controlled files, as demonstrated using Admin/changes.dat.
{
"affected": [
{
"package": {
"ecosystem": "PyPI",
"name": "golismero"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "0.6.3"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2012-0054"
],
"database_specific": {
"cwe_ids": [
"CWE-59"
],
"github_reviewed": true,
"github_reviewed_at": "2024-11-22T20:16:20Z",
"nvd_published_at": "2012-03-19T19:55:00Z",
"severity": "LOW"
},
"details": "libs/updater.py in GoLismero 0.6.3, and other versions before Git revision 2b3bb43d6867, as used in backtrack and possibly other products, allows local users to overwrite arbitrary files via a symlink attack on GoLismero-controlled files, as demonstrated using Admin/changes.dat.",
"id": "GHSA-vwxc-3cfr-37jq",
"modified": "2024-11-22T20:16:20Z",
"published": "2022-05-04T00:27:48Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2012-0054"
},
{
"type": "PACKAGE",
"url": "https://github.com/golismero/golismero"
},
{
"type": "WEB",
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/golismero/PYSEC-2012-31.yaml"
},
{
"type": "WEB",
"url": "http://code.google.com/p/golismero/source/detail?r=2b3bb43d68676efd687361f7de29380189031ab8"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2012/01/17/10"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2012/01/17/7"
}
],
"schema_version": "1.4.0",
"severity": [],
"summary": "GoLismero symlink attack"
}
Mitigation MIT-48.1
Strategy: Separation of Privilege
- Follow the principle of least privilege when assigning access rights to entities in a software system.
- Denying access to a file can prevent an attacker from replacing that file with a link to a sensitive file. Ensure good compartmentalization in the system to provide protected areas that can be trusted.
CAPEC-132: Symlink Attack
An adversary positions a symbolic link in such a manner that the targeted user or application accesses the link's endpoint, assuming that it is accessing a file with the link's name.
CAPEC-17: Using Malicious Files
An attack of this type exploits a system's configuration that allows an adversary to either directly access an executable file, for example through shell access; or in a possible worst case allows an adversary to upload a file and then execute it. Web servers, ftp servers, and message oriented middleware systems which have many integration points are particularly vulnerable, because both the programmers and the administrators must be in synch regarding the interfaces and the correct privileges for each interface.
CAPEC-35: Leverage Executable Code in Non-Executable Files
An attack of this type exploits a system's trust in configuration and resource files. When the executable loads the resource (such as an image file or configuration file) the attacker has modified the file to either execute malicious code directly or manipulate the target process (e.g. application server) to execute based on the malicious configuration parameters. Since systems are increasingly interrelated mashing up resources from local and remote sources the possibility of this attack occurring is high.
CAPEC-76: Manipulating Web Input to File System Calls
An attacker manipulates inputs to the target software which the target software passes to file system calls in the OS. The goal is to gain access to, and perhaps modify, areas of the file system that the target software did not intend to be accessible.