CWE-59

CWE-59 · 26 records · 19 with a public proof-of-concept

Records the NVD classes under CWE-59, highest CVSS first.

  1. CRITICAL 9.9CVE-2026-87799public PoC

    Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom storage volumes in a project, or a malicious m…

    AI risk analysis on Exploit-DB.ai →

  2. CRITICAL 9.9CVE-2026-100716public PoC

    Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to validate intermediate path components of the export destination: Froxlor\FileDir::makeCorrectDir() contains an off-by-one in its path-co…

    AI risk analysis on Exploit-DB.ai →

  3. CRITICAL 9.8CVE-2026-82331

    Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildStream running on Python < 3.12 allows malicious source tarballs to write files on the host, with the privileges of the user running BuildStr…

    AI risk analysis on Exploit-DB.ai →

  4. CRITICAL 9.6CVE-2026-100715public PoC

    Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task. Cron task 8 (deleteFtpData), queued when an FTP account is deleted, calls FileDir::makeCorrectDir() without the $fixed_homedir argument, s…

    AI risk analysis on Exploit-DB.ai →

  5. CRITICAL 9.1CVE-2026-101894public PoC

    The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel following a planted symlink chain. An attacker can supply a craf…

    AI risk analysis on Exploit-DB.ai →

  6. HIGH 8.8CVE-2026-85731public PoC

    oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, content/file.Store extraction of OCI layers marked with io.deis.oras.content.unpack=true can write outside the store working directory. The pushDir path through extractTarDirectory and ensureL…

    AI risk analysis on Exploit-DB.ai →

  7. HIGH 8.1CVE-2026-100838public PoC

    Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata agent policies generated by the Contrast CLI contained a flaw in the CopyFile verification that allowed arbitrary writes to the guest root filesystem. A malicious …

    AI risk analysis on Exploit-DB.ai →

  8. HIGH 7.8CVE-2026-12410

    Link following vulnerability in the Uninstaller component in CCleaner prior to 7.10.1464 on Windows allows a local, low-privileged attacker to escalate privileges to SYSTEM via a symlink/junction created during application uninstallation, which CCleaner follow…

    AI risk analysis on Exploit-DB.ai →

  9. HIGH 7.5CVE-2026-100692public PoC

    Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0, Hugo's symlink confinement checks stopped at the mount root itself, so a theme or module checked into themes/ (or a vendored module) could contain a symlink at a mount root (for e…

    AI risk analysis on Exploit-DB.ai →

  10. HIGH 7.5CVE-2026-100690public PoC

    Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js permission model to restrict file system reads to the project directory and configured mounts. Because the Node.js permission model valida…

    AI risk analysis on Exploit-DB.ai →

  11. HIGH 7CVE-2026-100419public PoC

    gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in the worktree checkout mechanism that allows attackers to escape the worktree directory via symlink manipulation. During forced checkout with overwrite_existing enabled, attackers …

    AI risk analysis on Exploit-DB.ai →

  12. MEDIUM 6.5CVE-2026-96279public PoC

    A malicious OCI registry can hardlink arbitrary host files into the extraction directory when a user installs or updates a Flatpak application from an OCI remote, allowing disclosure of arbitrary host file contents. For system-wide installs running as root, th…

    AI risk analysis on Exploit-DB.ai →

  13. MEDIUM 6.1CVE-2026-59944public PoC

    Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and from 2.3.0 until 2.10.3, a malicious or compromised dependency can bypass the earlier CVE-2026-59946 binary-path hardening because Composer validates literal parent-directory segm…

    AI risk analysis on Exploit-DB.ai →

  14. MEDIUM 5.9CVE-2026-86861public PoC

    pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested path with Filemanager.check_access_permission() and then opened the file for writing with a plain open() call. CVE-2026-7819 had previously har…

    pgadmin 4

    AI risk analysis on Exploit-DB.ai →

  15. MEDIUM 5.8CVE-2026-87798public PoC

    Improper link resolution in the recursive file pull feature of the LXD CLI client in Canonical LXD versions 4.0.2 up to 6.9 (fixed in 4.0.14, 5.0.10 and 5.21.8) on Linux allows an attacker with root access inside a virtual machine to write attacker-controlled …

    AI risk analysis on Exploit-DB.ai →

  16. MEDIUM 5.3CVE-2026-93353

    copyparty contains a volume restriction bypass vulnerability in its SFTP front end that allows authenticated SFTP users to create, remove, and truncate arbitrary paths outside permitted volume boundaries by exploiting three handlers that bypass the xvol volfla…

    AI risk analysis on Exploit-DB.ai →

  17. LOW 3.1CVE-2026-96282public PoC

    A malicious Flatpak extension can probe the host filesystem to determine what files and directories exist at arbitrary paths, and host directory listings can be disclosed to sandboxed applications using the extension. Additionally, unvalidated extension metada…

    AI risk analysis on Exploit-DB.ai →

  18. LOW 3CVE-2026-71182

    Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesyste…

    update package framework

    AI risk analysis on Exploit-DB.ai →

  19. LOW 3CVE-2026-71181

    Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesyste…

    update package framework

    AI risk analysis on Exploit-DB.ai →

  20. LOW 2.5CVE-2026-96284public PoC

    A malicious user can get read-access to files in the flatpak-system-helper context if a system OCI repository is configured, because the OCI code paths in the system helper follow symlinks when importing OCI images that are under the user's control.

    AI risk analysis on Exploit-DB.ai →

  21. UNSCOREDCVE-2026-80430public PoC

    Improper Link Resolution Before File Access in the drag source staging path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to create files and directories at paths outside the staging directory, becaus…

    AI risk analysis on Exploit-DB.ai →

  22. UNSCOREDCVE-2026-55074public PoC

    Ansible FreeBSD Jail Connection Plugin is an Ansible connection plugin for FreeBSD Jails via jexec. Through version 1.3.0, the jailexec connection plugin's put_file resolved a transfer's destination to a path on the jail host ( + ) and ran mkdir -p and mv ther…

    AI risk analysis on Exploit-DB.ai →

  23. UNSCOREDCVE-2026-92253

    Improper link resolution before file access in the quarantine restoration process of WatchDog Anti-Virus 1.8.640 on Windows allows local, low-privileged attackers to cause a quarantined file to be written to an arbitrary filesystem location by creating a direc…

    AI risk analysis on Exploit-DB.ai →

  24. UNSCOREDCVE-2026-54587public PoC

    mport is the MidnightBSD Package Manager. Prior to 2.7.8, directory assets handled as ASSET_DIR or ASSET_DIR_OWNER_MODE in libmport/bundle_read_install_pkg.c used path-based mport_mkdirp(), ownership, and permission operations. A local attacker able to modify …

    AI risk analysis on Exploit-DB.ai →

  25. UNSCOREDCVE-2026-54576public PoC

    mport is the MidnightBSD Package Manager. Prior to 2.7.8, do_actual_install() in libmport/bundle_read_install_pkg.c used path-based lstat(), chown(), stat(), and chmod() operations while installing package files. A local attacker with write access to a target …

    AI risk analysis on Exploit-DB.ai →

  26. UNSCOREDCVE-2026-68491

    An insufficient check allowed for the overwrite of arbitrary files via a symlink.

    AI risk analysis on Exploit-DB.ai →