Skip to main content

CWE archive

CWE-61 CVEs

Programmatic archive

157 CVEs tagged with CWE-619 Critical, 71 High, 67 Medium, 10 Low, 0 Unrated.

CVE-2026-56748

Published Jul 27, 2026

Improper validation of symbolic links in the Pack Git import feature in Cribl Stream before 4.18.2 allows a remote authenticated attacker with Pack import and pipeline preview per…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-17459

Published Jul 26, 2026

A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.externalLocation of the file src/main/java/spark/resource/Extern…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-65010

Published Jul 23, 2026

Datasets through 5.00, fixed in commit ad2d853, contains a symlink-following vulnerability in Extractor.extract() that allows local attackers to write arbitrary files by pre-plant…

CVSS 4.4 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2026-12080

Published Jul 20, 2026

A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-add-authorized-keys command handler by manipulating symbolic…

CVSS 7.3 · High
evidence mentions
4
Buzz score
32.6

CVE-2026-59674

Published Jul 14, 2026

A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed suricata package allows the suricata user to escalate to root. This issue affects openSUSE Tumb…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-39822

Published Jul 8, 2026

On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the p…

CVSS 7.8 · High
evidence mentions
5
Buzz score
37.9
Vendor/product tagsBeta · best-effort

CVE-2026-14699

Published Jul 5, 2026

A weakness has been identified in zcaceres markdownify-mcp up to 1.1.0. The affected element is the function assertPathAllowed of the file src/Markdownify.ts. Executing a manipula…

CVSS 4.8 · Medium
evidence mentions
7
Buzz score
27.3

CVE-2026-53489

Published Jul 1, 2026

containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a bug where the CRI plugin restores container.log from a checkpoint image without…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-41579

Published Jul 1, 2026

runc is a CLI tool for spawning and running containers according to the OCI specification. In versions prior to 1.3.6, 1.4.0-rc.1, 1.4.0-rc.12, 1.5.0-rc.1, and 1.5.0-rc.1, when se…

CVSS 3.3 · Low
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-13748

Published Jun 29, 2026

Improper restriction of file path resolution in Snowflake CLI versions prior to 3.19 allowed arbitrary local file content to be read and transmitted to Snowflake services. An atta…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-56876

Published Jun 26, 2026

extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/pa…

CVSS 8.6 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-55686

Published Jun 26, 2026

Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where the WORKDIR path contains a symlink can create a directory…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-13218

Published Jun 26, 2026

A flaw was found in KubeVirt's virt-handler network cache handling. The WriteToCachedFile function writes data to a launcher-rooted path using os.WriteFile and os.Chown without sy…

CVSS 4.2 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-52811

Published Jun 24, 2026

Gogs is an open source self-hosted Git service. Prior to 0.14.3, (*Repository).UploadRepoFiles checks for symlinks only on the leaf of the upload target (osx.IsSymlink(targetPath)…

CVSS 9.0 · Critical
evidence mentions
4
Buzz score
21.1

CVE-2026-13201

Published Jun 24, 2026

A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to obtain a file descriptor to a path leaf, but downstream…

CVSS 7.3 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-55447

Published Jun 23, 2026

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling a files that are digested into the RAG, an attacker can direct the no…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-12958

Published Jun 23, 2026

Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary. This may occur when a local user opens a workspac…

CVSS 8.5 · High
evidence mentions
4
Buzz score
32.6

CVE-2026-56815

Published Jun 23, 2026

pwnlift before d7a9544, in a privileged deployment, contains a symlink following vulnerability in the upload handler in Components/Pages/Home.razor.

CVSS 7.4 · High
evidence mentions
3
Buzz score
21.9

CVE-2026-49248

Published Jun 18, 2026

OneDev is a Git server with CI/CD, kanban, and packages. In versions 15.0.6 and below, TarUtils.untar() creates symbolic links verbatim from TAR entry getLinkName() without valida…

CVSS 8.3 · High
evidence mentions
2
Buzz score
16.0

CVE-2025-43278

Published Jun 11, 2026

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-5223

Published May 25, 2026

Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from th…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
36.1
Vendor/product tagsBeta · best-effort

CVE-2026-8784

Published May 18, 2026

A vulnerability was detected in npitre cramfs-tools up to 2.2. Affected is the function change_file_status of the file cramfsck.c. Performing a manipulation results in symlink fol…

CVSS 1.8 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-41937

Published May 14, 2026

Vvveb before 1.0.8.3 contains an unrestricted file upload vulnerability in the plugin upload endpoint that allows super_admin users to execute arbitrary PHP code by uploading a ma…

CVSS 8.6 · High
evidence mentions
3
Buzz score
20.4
Showing 1-25 of 157 CVEsPage 1 of 7