Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious
Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where
A logic error in the ln utility of uutils coreutils allows the utility to dereference a symbolic link target even when t
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0,
OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, skills/skill-creator/scripts/package_skill.py (a l
A security flaw has been discovered in NousResearch hermes-agent 0.8.0. This affects the function _check_sensitive_path
A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.exter
A vulnerability was detected in npitre cramfs-tools up to 2.2. Affected is the function change_file_status of the file c
A flaw was found in KubeVirt's virt-handler network cache handling. The WriteToCachedFile function writes data to a laun
runc is a CLI tool for spawning and running containers according to the OCI specification. In versions prior to 1.3.6, 1
A weakness has been identified in zcaceres markdownify-mcp up to 1.1.0. The affected element is the function assertPathA
Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host c
Nix is a package manager for Linux and other Unix systems. Prior to 2.35.0, a malicious derivation executed with the rec
OneDev is a Git server with CI/CD, kanban, and packages. In versions 15.0.6 and below, TarUtils.untar() creates symbolic
Gogs is an open source self-hosted Git service. Prior to 0.14.3, (*Repository).UploadRepoFiles checks for symlinks only
A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed suricata package allows the suricata user
pdm is a Python package and dependency manager supporting the latest PEP standards. In versions prior to 2.27.0, pdm wri
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prio
crun is an open source OCI Container Runtime fully written in C. Prior to version 1.28, crun's default device setup open
Youki is a container runtime written in Rust. In versions 0.5.6 and below, the initial validation of the source /dev/nul
Youki is a container runtime written in Rust. In versions 0.5.6 and below, youki’s apparmor handling performs insufficie
A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed cyrus-imapd allows escalation from cyrus t
Using Codex CLI in workspace-write mode inside a malicious context (repo, directory, etc) could lead to arbitrary file o
Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Versions 2.40.0 and be
NVIDIA Resiliency Extension for Linux contains a vulnerability in log aggregation, where an attacker could cause predict
The txtai framework allows the loading of compressed tar files as embedding indices. While the validate function is inte
Client RCE on macOS and Linux via improper symbolic link resolution in Google Web Designer's preview feature
Dell Encryption Admin Utilities versions prior to 11.10.2 contain an Improper Link Resolution vulnerability. A local mal
runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below,
WebPros Plesk before 18.0.73.5 and 18.0.74 before 18.0.74.2 on Linux allows remote authenticated users to execute arbitr
pwn.college is an education platform to learn about, and practice, core cybersecurity concepts in a hands-on fashion. In
runc is a CLI tool for spawning and running containers according to the OCI specification. Versions 1.0.0-rc3 through 1.
runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7, 1.3.2 and
Dell SupportAssist OS Recovery versions prior to 5.5.13.1 contain a symbolic link attack vulnerability. A low-privileged
Youki is a container runtime written in Rust. Prior to version 0.5.5, if /proc and /sys in the rootfs are symbolic links
When running the AWS Serverless Application Model Command Line Interface (SAM CLI) build process with Docker and symlink
After completing a build with AWS Serverless Application Model Command Line Interface (SAM CLI) which include symlinks,
Claude Code is an agentic coding tool. Versions below 1.0.120 failed to account for symlinks when checking permission de
SupportAssist for Home PCs versions 4.8.2 and prior and SupportAssist for Business PCs versions 4.5.3 and prior, contain
UNIX symbolic link (Symlink) following issue exists in FutureNet NXR series, VXR series and WXR series routers. Attachin
A vulnerability has been found in Ugreen DH2100+ up to 5.3.0. This affects an unknown function of the component USB Hand
Arbitrary file overwrite during home directory recovery due to improper symbolic link handling. The following products a
The WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebA
Improper handling of symbolic links in Ivanti Connect Secure before version 22.7R2.8 or 22.8R2, Ivanti Policy Secure bef
Symlink following in the installer for some Zoom apps for macOS before version 6.1.5 may allow an authenticated user to
A security vulnerability has been detected in wonderwhy-er DesktopCommanderMCP up to 0.2.13. This vulnerability affects
SingularityCE and SingularityPRO are open source container platforms. Prior to SingularityCE 4.3.5 and SingularityPRO 4.
Apptainer is an open source container platform. In Apptainer versions less than 1.4.5, a container can disable two of th
Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, users can craft a "Time of Check to Time
`zip` is a zip library for rust which supports reading and writing of simple ZIP files. In the archive extraction routin
Frequently Asked Questions
What is CWE-61?
CWE-61 (CWE-61) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-61?
There are 168 CVE records associated with CWE-61 in our database. Of these, 12 are critical severity, 70 are high severity, and 66 are medium severity.
How can I protect against CWE-61 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-61 using AI-powered security agents.
Detect CWE-61 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-61 vulnerabilities across your infrastructure.
Get Started