目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-59 在文件访问前对链接解析不恰当(链接跟随) 类漏洞列表 641

CWE-59 在文件访问前对链接解析不恰当(链接跟随) 类弱点 641 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-59 属于文件访问类漏洞,指程序在访问文件前未正确验证链接解析结果。攻击者常通过创建指向敏感资源的符号链接或快捷方式,诱导程序读取非预期文件,从而引发信息泄露或权限提升。开发者应避免直接使用用户输入的文件名,需在访问前校验最终解析路径,确保其位于预期的安全目录内,防止链接劫持风险。

MITRE CWE 官方描述
CWE:CWE-59 文件访问前链接解析不当('Link Following') 英文:产品尝试基于文件名访问文件,但未能正确防止该文件名标识解析到非预期资源的链接或快捷方式。
常见影响 (2)
Confidentiality, Integrity, Access Control Read Files or Directories, Modify Files or Directories, Bypass Protection Mechanism
An attacker may be able to traverse the file system to unintended locations and read or overwrite the contents of unexpected files. If the files are used for a security mechanism then an attacker may be able to bypass the mechanism.
Other Execute Unauthorized Code or Commands
Windows simple shortcuts, sometimes referred to as soft links, can be exploited remotely since a ".LNK" file can be uploaded like a normal file. This can enable remote execution.
缓解措施 (1)
Architecture and Design Follow the principle of least privilege when assigning access rights to entities in a software system. Denying access to a file can prevent an attacker from replacing that file with a link to a sensitive file. Ensure good compartmentalization in the system to provide protected areas that can be trusted.
CVE ID 标题 CVSS 风险等级 Published
CVE-2026-82049 Python CPython 后置链接漏洞 — CPython 8.4 High 2026-09-14
CVE-2026-89021 MikroTik RouterOS 路径遍历漏洞 — RouterOS 6.9 Medium 2026-09-14
CVE-2026-90807 NanoCo NanoClaw 后置链接漏洞 — NanoClaw 6.3 Medium 2026-09-14
CVE-2026-90930 FileBrowser 后置链接漏洞 — filebrowser 6.8 Medium 2026-09-14
CVE-2026-89258 Gohugoio Hugo 后置链接漏洞 — hugo 6.3 Medium 2026-09-11
CVE-2026-88016 Rclone 权限许可和访问控制问题漏洞 — rclone 7.1 High 2026-09-10
CVE-2026-88265 Containers crun 后置链接漏洞 — Red Hat Enterprise Linux 10 5.6 Medium 2026-09-10
CVE-2026-88264 Containers crun 后置链接漏洞 — crun 5.6 Medium 2026-09-10
CVE-2026-87766 Containers Bubblewrap 后置链接漏洞 — Red Hat Enterprise Linux 10 8.8 High 2026-09-09
CVE-2026-78622 Okta Verify for Windows 后置链接漏洞 — Okta Verify for Windows 6.0 Medium 2026-09-08
CVE-2026-81963 Microsoft Windows Update Stack 权限许可和访问控制问题漏洞 — Windows 11 version 23H2 7.8 High 2026-09-08
CVE-2026-69425 Microsoft Windows NTFS 后置链接漏洞 — Windows 11 version 23H2 4.7 Medium 2026-09-08
CVE-2026-69289 Microsoft Windows 后置链接漏洞 — Windows 10 Version 1607 7.8 High 2026-09-08
CVE-2026-83999 Microsoft Windows Resilient File System 后置链接漏洞 — Windows 11 Version 24H2 7.0 High 2026-09-08
CVE-2026-70563 Microsoft Windows Shell 后置链接漏洞 — Windows 10 Version 1607 8.1 High 2026-09-08
CVE-2026-69771 Microsoft Windows Container Manager Service 后置链接漏洞 — Windows 11 version 23H2 4.7 Medium 2026-09-08
CVE-2026-69379 Microsoft Windows NTFS 后置链接漏洞 — Windows 11 version 23H2 7.0 High 2026-09-08
CVE-2026-68830 Microsoft Windows Universal Plug and Play 权限许可和访问控制问题漏洞 — Windows 10 Version 1607 5.5 Medium 2026-09-08
CVE-2026-67368 Microsoft SQL Server 后置链接漏洞 — Microsoft SQL Server 2017 (CU 31) 8.8 High 2026-09-08
CVE-2026-86469 GNOME glib 后置链接漏洞 — Red Hat Enterprise Linux 10 5.3 Medium 2026-09-07
CVE-2026-86424 ImageMagick 后置链接漏洞 — ImageMagick 2.5 Low 2026-09-07
CVE-2026-86422 ImageMagick 后置链接漏洞 — ImageMagick 3.3 Low 2026-09-07
CVE-2026-85583 SiYuan 后置链接漏洞 — siyuan 6.5 Medium 2026-09-04
CVE-2026-85092 Joe Sylve LiME 后置链接漏洞 — LiME 6.6 Medium 2026-09-03
CVE-2026-78409 util-linux 后置链接漏洞 — Red Hat Hardened Images 7.0 High 2026-09-02
CVE-2024-14047 Elastic Security 后置链接漏洞 — Elastic Security 7.2 High 2026-09-01
CVE-2026-55108 KubeVela 资源管理错误漏洞 — kubevela 8.5 High 2026-08-28
CVE-2026-82252 GitoxideLabs gitoxide 后置链接漏洞 — gitoxide 7.5 High 2026-08-28
CVE-2026-82248 GitoxideLabs gitoxide 后置链接漏洞 — gitoxide 5.3 Medium 2026-08-28
CVE-2026-81727 Natural Language Toolkit 后置链接漏洞 — nltk 7.1 High 2026-08-27

CWE-59(在文件访问前对链接解析不恰当(链接跟随)) 是常见的弱点类别,本平台收录该类弱点关联的 641 条 CVE 漏洞。