CWE-61Compound1 in KEV

UNIX Symbolic Link (Symlink) Following

Incomplete in the CWE catalog · 160 CVEs mapped

160
CVEs mapped
1
In KEV
7.0
Median CVSS
What it is

The product, when opening a file or directory, does not sufficiently account for when the file is a symbolic link that resolves to a target outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.

Recent examples
5.8cvss
CVE-2026-79939

CVE-2026-79939 - MEDIUM Severity Vulnerability

Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Script injection.

MEDIUMno explanation yet
0%
epss
6.1cvss
CVE-2026-75038

CVE-2026-75038 - MEDIUM Severity Vulnerability

UNIX symbolic link (symlink) following vulnerability in ilya-zlobintsev/LACT allows for local denial-of-service. This issue affects LACT: through 0.10.0.

MEDIUMno explanation yet
0%
epss
6.5cvss
CVE-2026-55168

CVE-2026-55168 - MEDIUM Severity Vulnerability

Runtipi is a personal homeserver orchestrator. In 4.10.0 and earlier, Runtipi accepts symbolic links from an attacker-controlled backup archive and copies them into live application paths during the backup restore flow. An authenticated attacker can plant user-config/app.env as a symlink to an arbitrary reachable path and then send PUT /api/user-config/demoapp3:_user with attacker-controlled appEnv content. FilesystemService.writeTextFile() follows the planted link, allowing content to be written outside the intended restore and user-config directory boundary with Runtipi process permissions. This issue is fixed in version 4.10.1.

MEDIUMno explanation yet
1%
epss
The record
Technical detail
CWE ID
CWE-61
Abstraction
Compound
Structure
Composite
Status
Incomplete
References (2)