Kenwood DNR1007XR Firmware Update Link Following Code Execution Vulnerability. This vulnerability allows physically pres
A local unprivileged user on the same host can redirect all Zip/UnZip transformer output into a directory of their choos
A vulnerability in the rm utility of uutils coreutils allows a bypass of the --preserve-root protection. The implementat
Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to el
Tanium addressed a documentation issue in Engage.
Dell Display and Peripheral Manager (Windows) versions prior to 2.2 contain an Improper Link Resolution Before File Acce
During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during ins
python-dotenv reads key-value pairs from a .env file and can set them as environment variables. Prior to version 1.2.2,
The mv utility in uutils coreutils improperly handles directory trees containing symbolic links during moves across file
radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to re
FlashAttention through 2.8.3.post1, fixed in commit 0816ef1, contains a symlink attack vulnerability in the download_and
Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnera
Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Link Resolution Before File Access ('Link Follow
aqua is a declarative command-line version manager written in Go. Prior to 2.60.1, pkg/unarchive/archives.go in the hand
pnpm is a package manager. Prior to version 10.28.2, when pnpm installs a `file:` (directory) or `git:` dependency, it f
OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in browser trace and download output path
A Dag author could either (a) create a symlink under their task's log directory pointing to an arbitrary file readable b
Hermes WebUI prior to v0.51.221 contains a path traversal vulnerability that allows attackers to escape the workspace bo
Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Debian source packages
Runtipi is a personal homeserver orchestrator. In versions 4.9.1 through 4.9.3, Runtipi serves marketplace app logos fro
Hugo is a static site generator. From v0.123.0 through v0.163.0, Hugo's virtual filesystem is designed so that files und
AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create an
A vulnerability in the `zipx.Unzip` extraction routine of Develar's app-builder allows an attacker to overwrite arbitrar
tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function t
CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file manager component t
Runtipi is a personal homeserver orchestrator. In 4.10.0 and earlier, Runtipi accepts symbolic links from an attacker-co
adm-zip 0.5.9 through 0.6.0 follows symbolic links at the extraction destination. Utils.sanitize in util/utils.js enforc
On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can ope
Confidential Containers Guest Components provides guest tools and components for confidential container workloads. From
Backstage is an open framework for building developer portals, and @backstage/cli-common provides config loading functio
Improper link resolution in the VX800v v1.0 SFTP service allows authenticated adjacent attackers to use crafted symbolic
node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that p
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
Dell/Alienware Purchased Apps, versions prior to 1.1.31.0, contain an Improper Link Resolution Before File Access ('Link
Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an una
Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod,
Dell/Alienware Purchased Apps, versions prior to 1.1.32.0, contain an Improper Link Resolution Before File Access ('Link
File Browser provides a web file managing interface. Prior to 2.63.16, ScopedFs validates the nearest existing ancestor
A weakness has been identified in louisho5 picobot up to 0.2.0. Impacted is the function CreateSkill/GetSkill of the fil
A vulnerability was identified in mf-yang openclaw-cn up to 0.2.1. This issue affects the function assertNoSymlinkEscape
rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the non-daemon recei
rsync before 3.5.0 contains a symlink race condition vulnerability that allows local attackers to cause rsync to apply a
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to improper
This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS
Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tamper
Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_NOFOL
NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to
The ORICO NAS CD3510 (version V1.9.12 and below) contains an Incorrect Symlink Follow vulnerability that could be exploi
An Incorrect Symlink Follow vulnerability exists in multiple Yottamaster NAS devices, including DM2 (version equal to or
The ZSPACE Q2C NAS contains a vulnerability related to incorrect symbolic link following. Attackers can format a USB dri
Frequently Asked Questions
What is CWE-59?
CWE-59 (CWE-59) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-59?
There are 1,879 CVE records associated with CWE-59 in our database. Of these, 45 are critical severity, 691 are high severity, and 425 are medium severity.
How can I protect against CWE-59 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-59 using AI-powered security agents.
Detect CWE-59 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-59 vulnerabilities across your infrastructure.
Get Started