CWE-62: UNIX Hard Link
The product, when opening a file or directory, does not sufficiently account for when the name is associated with a hard link to a target that is outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.
3 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-32232 — ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink
- CVE-2024-36486 — A privilege escalation vulnerability exists in the virtual machine archive restoration functionality of Parallels Deskto
Recently published
- CVE-2026-32232 — ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink
- CVE-2024-36486 — A privilege escalation vulnerability exists in the virtual machine archive restoration functionality of Parallels Deskto