The product, when opening a file or directory, does not sufficiently account for when the file is a symbolic link that resolves to a target outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.
Volume of CVEs assigned to CWE-61 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
154 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-54420HIGH LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting | Jun 14, 2026 | 8.5 | 77 | YES | NO |
CVE-2024-28185CRITICAL Judge0 is an open-source online code execution system. The application does not account for symlinks placed inside the sandbox directory, which can be leveraged by an attacker to w | Apr 18, 2024 | 10.0 | 45 | NO | YES |
CVE-2024-28189CRITICAL Judge0 is an open-source online code execution system. The application uses the UNIX chown command on an untrusted file within the sandbox. An attacker can abuse this by creating a | Apr 18, 2024 | 10.0 | 44 | NO | YES |
CVE-2026-55447CRITICAL Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling a files that are digested into the RAG, an attacker can direct the nod | Jun 23, 2026 | 9.6 | 41 | NO | NO |
CVE-2026-52811CRITICAL Gogs is an open source self-hosted Git service. Prior to 0.14.3, (*Repository).UploadRepoFiles checks for symlinks only on the leaf of the upload target (osx.IsSymlink(targetPath)) | Jun 24, 2026 | 9.0 | 39 | NO | NO |
CVE-2026-29203HIGH A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on arbitrary system files or directories. That can cause DoS or | May 8, 2026 | 8.8 | 39 | NO | NO |
CVE-2026-34078CRITICAL Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled sy | Apr 7, 2026 | 10.0 | 39 | NO | NO |
CVE-2026-39822HIGH On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the pa | Jul 8, 2026 | 7.8 | 38 | NO | NO |
CVE-2026-12958HIGH Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary. This may occur when a local user opens a workspace | Jun 23, 2026 | 7.8 | 37 | NO | NO |
CVE-2026-56876HIGH extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/pas | Jun 26, 2026 | 8.1 | 36 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.