目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-59 在文件访问前对链接解析不恰当(链接跟随) 类漏洞列表 638

CWE-59 在文件访问前对链接解析不恰当(链接跟随) 类弱点 638 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-59 属于文件访问类漏洞,指程序在访问文件前未正确验证链接解析结果。攻击者常通过创建指向敏感资源的符号链接或快捷方式,诱导程序读取非预期文件,从而引发信息泄露或权限提升。开发者应避免直接使用用户输入的文件名,需在访问前校验最终解析路径,确保其位于预期的安全目录内,防止链接劫持风险。

MITRE CWE 官方描述
CWE:CWE-59 文件访问前链接解析不当('Link Following') 英文:产品尝试基于文件名访问文件,但未能正确防止该文件名标识解析到非预期资源的链接或快捷方式。
常见影响 (2)
Confidentiality, Integrity, Access Control Read Files or Directories, Modify Files or Directories, Bypass Protection Mechanism
An attacker may be able to traverse the file system to unintended locations and read or overwrite the contents of unexpected files. If the files are used for a security mechanism then an attacker may be able to bypass the mechanism.
Other Execute Unauthorized Code or Commands
Windows simple shortcuts, sometimes referred to as soft links, can be exploited remotely since a ".LNK" file can be uploaded like a normal file. This can enable remote execution.
缓解措施 (1)
Architecture and Design Follow the principle of least privilege when assigning access rights to entities in a software system. Denying access to a file can prevent an attacker from replacing that file with a link to a sensitive file. Ensure good compartmentalization in the system to provide protected areas that can be trusted.
CVE ID 标题 CVSS 风险等级 Published
CVE-2026-81310 Linux图像扫描驱动存在链接跟随漏洞 — Image Scanner Driver for Linux (fi Series) 6.6 Medium 2026-09-30
CVE-2026-102242 MCP Toolbox for Databases 符号链接路径遍历漏洞 — MCP Toolbox for Databases 8.6 High 2026-09-29
CVE-2026-92371 Cloud Session Recording 本地提权漏洞 — Full Client 7.0 High 2026-09-29
CVE-2026-87798 LXD 客户端递归文件拉取允许通过恶意虚拟机代理实现目录逃逸 — LXD 5.8 Medium 2026-09-28
CVE-2026-87799 LXD 主机上通过迁移流中的符号链接实现任意文件写入 — LXD 9.9 Critical 2026-09-28
CVE-2026-96284 Flatpak 系统助手上下文通过 OCI 符号链接跟随实现任意文件读取漏洞 — Red Hat Enterprise Linux 10 2.5 Low 2026-09-27
CVE-2026-96282 Flatpak 扩展元数据路径遍历漏洞 — Red Hat Enterprise Linux 10 3.1 Low 2026-09-27
CVE-2026-96279 Flatpak OCI归档提取路径穿越漏洞 — Red Hat Enterprise Linux 10 6.5 Medium 2026-09-27
CVE-2026-100838 Contrast 1.19.1以下 CopyFile策略符号链接漏洞 — contrast 8.1 High 2026-09-27
CVE-2026-100716 Froxlor <2.3.12 通过软链接的权限提升漏洞 — froxlor 9.9 Critical 2026-09-26
CVE-2026-100715 Froxlor 2.3.12 前任意文件删除漏洞 — froxlor 9.6 Critical 2026-09-26
CVE-2026-100692 Hugo <0.166.0 通过符号链接挂载根路径遍历漏洞 — hugo 7.5 High 2026-09-26
CVE-2026-100690 Hugo v0.161.0-v0.165.0 符号链接任意文件读取漏洞 — hugo 7.5 High 2026-09-26
CVE-2026-100419 gitoxide gix-fs 0.23.0前工作区符号链接逃逸漏洞 — gitoxide 7.0 High 2026-09-25
CVE-2026-80430 Kitty拖放协议链接解析不当导致任意文件创建漏洞 — kitty 4.6 Medium 2026-09-25
CVE-2026-93353 copyparty SFTP卷限制绕过漏洞 — copyparty 5.3 Medium 2026-09-24
CVE-2026-82331 Apache BuildStream tar源提取逃逸漏洞 — Apache BuildStream - - 2026-09-23
CVE-2026-55074 Ansible FreeBSD Jail插件符号链接逃逸漏洞 — ansible_jailexec 8.2 High 2026-09-21
CVE-2026-92253 WatchDog防病毒隔离恢复任意文件写入漏洞 — Anti-Virus 5.2 Medium 2026-09-20
CVE-2026-15815 无法翻译,提供的文本仅为 CVE 编号及记录标题,缺少具体的受影响软件、版本及漏洞类型信息。 — Grafana OSS 8.8 High 2026-09-17
CVE-2026-54576 包安装符号链接处理TOCTOU漏洞 — mport 5.8 Medium 2026-09-17
CVE-2026-54587 导入目录资产安装时的符号链接与路径遍历竞态漏洞 — mport 5.8 Medium 2026-09-17
CVE-2026-71182 Dell Update Package Framework 26.07.03前路径遍历漏洞 — Update Package Framework 3.0 Low 2026-09-16
CVE-2026-71181 Dell Update Package Framework 26.07.03 前链接跟随漏洞 — Update Package Framework 3.0 Low 2026-09-16
CVE-2026-68491 符号链接导致任意文件覆写的检查不足 — SolusVM 9.4 Critical 2026-09-15
CVE-2026-79699 Podman等容器组件tar白名单目录替换漏洞 — Red Hat Ansible Automation Platform 2 4.4 Medium 2026-09-15
CVE-2026-77179 Docker沙箱符号链接任意写宿主机文件漏洞 — Docker Sandboxes 9.4 Critical 2026-09-15
CVE-2026-82049 Python CPython 后置链接漏洞 — CPython 8.4 High 2026-09-14
CVE-2026-89021 MikroTik RouterOS 路径遍历漏洞 — RouterOS 6.9 Medium 2026-09-14
CVE-2026-90807 NanoCo NanoClaw 后置链接漏洞 — NanoClaw 6.3 Medium 2026-09-14

CWE-59(在文件访问前对链接解析不恰当(链接跟随)) 是常见的弱点类别,本平台收录该类弱点关联的 638 条 CVE 漏洞。