CWE-61: UNIX Symbolic Link (Symlink) Following
The product, when opening a file or directory, does not sufficiently account for when the file is a symbolic link that resolves to a target outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.
160 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-54420 — LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provide
- CVE-2024-28189 — Judge0 vulnerable to Sandbox Escape Patch Bypass via chown running on Symbolic Link
- CVE-2024-28185 — Judge0 vulnerable to Sandbox Escape via Symbolic Link
- CVE-2025-68937 — Forgejo before 13.0.2 allows attackers to write to unintended files, and possibly obtain server shell access, because of
- CVE-2025-55345 — Unsafe symlink following in restricted workspace-write sandbox leads to RCE
- CVE-2025-59343 — tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball
- CVE-2025-57802 — Airlink's Daemon Symlink Vulnerability
- CVE-2025-46810 — A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of openSUSE Tumbleweed traefik2 allows the traef
- CVE-2025-52565 — container escape due to /dev/console mount and related races
- CVE-2025-33225 — NVIDIA Resiliency Extension for Linux contains a vulnerability in log aggregation, where an attacker could cause predict
- CVE-2026-63125 — Incus vulnerable to root RCE via image backup.yaml symlink
- CVE-2025-10854 — Symlink Following in txtai leads to arbitrary file write when loading untrusted embedding indices
- CVE-2024-47515 — Pagure: generate_archive() follows symbolic links in temporary clones
- CVE-2026-55447 — Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
- CVE-2026-34078 — Flatpak has a complete sandbox escape leading to host file access and code execution in the host context
- CVE-2025-66431 — WebPros Plesk before 18.0.73.5 and 18.0.74 before 18.0.74.2 on Linux allows remote authenticated users to execute arbitr
- CVE-2025-36564 — Dell Encryption Admin Utilities versions prior to 11.10.2 contain an Improper Link Resolution vulnerability. A local mal
- CVE-2025-1079 — RCE In Google Web Designer
- CVE-2024-47480 — Dell Inventory Collector Client, versions prior to 12.7.0, contains an Improper Link Resolution Before File Access vulne
- CVE-2025-24886 — pwn.college has Symlink LFI in Dojo repos
Recently published
- CVE-2026-57825 — In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishan
- CVE-2026-79939 — Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Symbolic Link (Symlink) Following vulnerabilit
- CVE-2026-75038 — Predictable temporary file in /tmp allows symlink attack in LACT
- CVE-2026-55168 — Runtipi: Authenticated arbitrary file write via backup restore symlink planting
- CVE-2026-63125 — Incus vulnerable to root RCE via image backup.yaml symlink
- CVE-2026-64846 — Nix: Arbitrary file truncation outside the sandbox with recursive-nix experimental feature
- CVE-2026-32657 — Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, D
- CVE-2026-47766 — crun follows rootfs /dev symlink while creating default devices
- CVE-2026-53802 — rsync < 3.5.0 Arbitrary File Read via Symlink Following
- CVE-2026-62992 — Smarty: Symlink path traversal out of trusted directories
- CVE-2026-47763 — pdm: Project-Local State and Config Writes Follow Symlinks
- CVE-2026-54574 — `proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive
- CVE-2026-56748 — Authenticated RCE via Symlink Following in Cribl Stream Pack Git Import
- CVE-2026-17459 — perwendel spark SparkJava ExternalResourceHandler.jav staticFiles.externalLocation symlink
- CVE-2026-65010 — Datasets Symlink-following Arbitrary File Write via Extractor.extract()
- CVE-2026-12080 — Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys
- CVE-2026-59674 — LPE from suricata user to root due to chown in %post in suricata packaging
- CVE-2026-14699 — zcaceres markdownify-mcp Markdownify.ts assertPathAllowed symlink
- CVE-2026-53489 — containerd: Arbitrary host CRI log file read via symlink following in CRI checkpoint restore
- CVE-2026-41579 — runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations