Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths
A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with ed
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t
A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host
A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During th
Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus
A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers
Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by
A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN),
Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packages/server/src/api/ro
Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded fil
SSHFS is a network filesystem client for connecting to SSH servers. Prior to version 3.7.6, a rogue SFTP server can retu
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction dire
Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processi
The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files an
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering t
Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:from-archive and certs:add commands extract user-supplied tar/z
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Prior to 3.1.0 and 2.3.8, the himmelbla
Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar a
OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in the agents.files.get and agents.files.
Improper link resolution before file access ('link following') vulnerability in TUBITAK BILGEM Software Technologies Res
CyberPanel 2.1 contains a command execution vulnerability that allows authenticated attackers to read arbitrary files an
Froxlor is open source server administration software. Version 2.3.6 contains a symlink-following flaw in the root-owned
Claude Code is an agentic coding tool. From 2.1.38 until 2.1.163, Claude Code's worktree handling allowed creation of w
Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.6. An app may be ab
HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job s
JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, the upload_wasm MCP tool accepted a
vm2 is an open source vm/sandbox for Node.js. In 3.10.5, NodeVM's require.root path restriction can be bypassed using fi
KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until 1.10.9, and from 1.
Compressing is a compressing and uncompressing lib for node. In version 2.0.0 and 1.10.3 and prior, Compressing extracts
In multiple locations, there is a possible way to delete media without the MANAGE_EXTERNAL_STORAGE permission due to an
Compressing is a compressing and uncompressing lib for node. Prior to 2.1.1 and 1.10.5, the patch for CVE-2026-24884 rel
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From 0.4.0 to befo
Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to
Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job::createLockFile() that allows local a
node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink en
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
filebrowser versions before 2.63.19 contain an out-of-scope file deletion vulnerability in the TUS upload cache eviction
OpenClaw before 2026.3.31 contains a symlink following vulnerability in SSH sandbox tar upload that allows remote attack
An improper link resolution vulnerability in Netatalk 3.0.2 through 4.4.2 allows a remote authenticated attacker to read
ProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass vulnerability that allows authenticated FTP users
rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricte
rsync before 3.5.0 contains an arbitrary file write vulnerability that allows attackers to write files outside the inten
rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module roo
extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own f
py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryptio
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, symlink attacks on pa
Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized at
Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.
Frequently Asked Questions
What is CWE-59?
CWE-59 (CWE-59) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-59?
There are 327 CVE records associated with CWE-59 in our database. Of these, 17 are critical severity, 129 are high severity, and 132 are medium severity.
How can I protect against CWE-59 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-59 using AI-powered security agents.
Detect CWE-59 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-59 vulnerabilities across your infrastructure.
Get Started