目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-59 在文件访问前对链接解析不恰当(链接跟随) 类漏洞列表 641

CWE-59 在文件访问前对链接解析不恰当(链接跟随) 类弱点 641 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-59 属于文件访问类漏洞,指程序在访问文件前未正确验证链接解析结果。攻击者常通过创建指向敏感资源的符号链接或快捷方式,诱导程序读取非预期文件,从而引发信息泄露或权限提升。开发者应避免直接使用用户输入的文件名,需在访问前校验最终解析路径,确保其位于预期的安全目录内,防止链接劫持风险。

MITRE CWE 官方描述
CWE:CWE-59 文件访问前链接解析不当('Link Following') 英文:产品尝试基于文件名访问文件,但未能正确防止该文件名标识解析到非预期资源的链接或快捷方式。
常见影响 (2)
Confidentiality, Integrity, Access Control Read Files or Directories, Modify Files or Directories, Bypass Protection Mechanism
An attacker may be able to traverse the file system to unintended locations and read or overwrite the contents of unexpected files. If the files are used for a security mechanism then an attacker may be able to bypass the mechanism.
Other Execute Unauthorized Code or Commands
Windows simple shortcuts, sometimes referred to as soft links, can be exploited remotely since a ".LNK" file can be uploaded like a normal file. This can enable remote execution.
缓解措施 (1)
Architecture and Design Follow the principle of least privilege when assigning access rights to entities in a software system. Denying access to a file can prevent an attacker from replacing that file with a link to a sensitive file. Ensure good compartmentalization in the system to provide protected areas that can be trusted.
CVE ID 标题 CVSS 风险等级 Published
CVE-2025-34194 Vasion Print和Vasion Print Virtual Appliance Host 安全漏洞 — Print Virtual Appliance Host 7.8 - 2025-09-19
CVE-2025-55317 Microsoft AutoUpdate for Mac 后置链接漏洞 — Microsoft AutoUpdate for Mac 7.8 High 2025-09-09
CVE-2025-55245 Microsoft Xbox Gaming Services 后置链接漏洞 — Xbox Gaming Services 7.8 High 2025-09-09
CVE-2025-58373 Roo Code 后置链接漏洞 — Roo-Code 5.5 Medium 2025-09-05
CVE-2025-43726 Dell Alienware Command Center 后置链接漏洞 — Alienware Command Center 5.x (AWCC) 6.7 Medium 2025-09-02
CVE-2025-57749 n8n 后置链接漏洞 — n8n 6.5 Medium 2025-08-20
CVE-2025-8612 AOMEI Backupper Workstation 后置链接漏洞 — Backupper Workstation 7.3 - 2025-08-20
CVE-2025-5296 Schneider Electric SESU 后置链接漏洞 — SESU 7.3 High 2025-08-18
CVE-2025-8959 HashiCorp go-getter 安全漏洞 — Shared library 7.5 High 2025-08-15
CVE-2025-43490 HP Hotkey Support 安全漏洞 — HP Hotkey Support Software 7.8AI High AI 2025-08-15
CVE-2025-55188 7-Zip 安全漏洞 — 7-Zip 3.6 Low 2025-08-08
CVE-2025-54798 tmp 安全漏洞 — node-tmp 2.5 Low 2025-08-07
CVE-2025-36611 Dell Security Management Server和Dell Encryption 后置链接漏洞 — Encryption 7.3 High 2025-07-30
CVE-2025-23267 NVIDIA Container Toolkit 后置链接漏洞 — Container Toolkit 8.5 High 2025-07-17
CVE-2025-7012 Cato Networks Cato Client for Linux 安全漏洞 — Cato Client 7.8AI High AI 2025-07-13
CVE-2025-49739 Microsoft Visual Studio 后置链接漏洞 — Microsoft Visual Studio 2015 Update 3 8.8 High 2025-07-08
CVE-2025-49738 Microsoft PC Manager 后置链接漏洞 — Microsoft PC Manager 7.8 High 2025-07-08
CVE-2025-49680 Microsoft Windows 后置链接漏洞 — Windows 10 Version 1507 7.3 High 2025-07-08
CVE-2025-48820 Microsoft Windows AppX Deployment Service 后置链接漏洞 — Windows 10 Version 1507 7.8 High 2025-07-08
CVE-2025-48799 Microsoft Windows Update 后置链接漏洞 — Windows 10 Version 1607 7.8 High 2025-07-08
CVE-2025-21195 Microsoft Service Fabric 后置链接漏洞 — Service Fabric 6.0 Medium 2025-07-08
CVE-2025-41668 PHOENIX CONTACT多款产品 后置链接漏洞 — AXC F 1152 8.8 High 2025-07-08
CVE-2025-41667 PHOENIX CONTACT多款产品 后置链接漏洞 — AXC F 1152 8.8 High 2025-07-08
CVE-2025-41666 PHOENIX CONTACT多款产品 后置链接漏洞 — AXC F 1152 8.8 High 2025-07-08
CVE-2025-53109 Model Context Protocol Servers 后置链接漏洞 — servers 4.3AI Medium AI 2025-07-02
CVE-2025-3771 Trellix System Information Reporter 安全漏洞 — System Information Reporter 7.1AI High AI 2025-06-26
CVE-2025-52936 sslh 后置链接漏洞 — sslh 9.3 Critical 2025-06-23
CVE-2025-30642 Trend Micro Deep Security 安全漏洞 — Trend Micro Deep Security 5.5 Medium 2025-06-17
CVE-2025-30641 Trend Micro Deep Security 安全漏洞 — Trend Micro Deep Security 7.8 High 2025-06-17
CVE-2025-30640 Trend Micro Deep Security 安全漏洞 — Trend Micro Deep Security 7.8 High 2025-06-17

CWE-59(在文件访问前对链接解析不恰当(链接跟随)) 是常见的弱点类别,本平台收录该类弱点关联的 641 条 CVE 漏洞。