CWE-61: CWE-61

43
Total CVEs
2
Critical
21
High
6.8
Avg CVSS

Yearly Trend

2026
5
2025
21
2024
13
2021
4

Top Affected Vendors

1 Dell 6
2 Linuxfoundation 3
3 Cisco 2
4 Copier Org 2
5 Zoom 1
6 Youki Dev 1
7 Suse 1
8 Aiohttp 1
9 Openclaw 1
10 Zscaler 1

All CWE-61 CVEs (43)

CVE-2025-23394
9.8

A UNIX symbolic link following vulnerability in cyrus-imapd on openSUSE Tumbleweed allows local attackers to escalate privileges from the cyrus user t...

May 26, 2025
CVE-2024-54661
9.8

This vulnerability in socat's readline.sh script allows local privilege escalation through insecure temporary file handling. Attackers can exploit sym...

Dec 4, 2024
CVE-2025-55345
8.8

This vulnerability in Codex CLI allows attackers to overwrite arbitrary files and potentially achieve remote code execution when the tool is used in w...

Aug 13, 2025
CVE-2024-22014
8.8

This vulnerability in 360 Total Security Antivirus allows attackers to escalate privileges by exploiting symbolic link following to delete arbitrary f...

Apr 15, 2024
CVE-2025-67487
8.6

This vulnerability in Static Web Server (SWS) allows attackers who can create files in the web root directory to create symbolic links that escape the...

Dec 9, 2025
CVE-2021-39134
8.2

This vulnerability in @npmcli/arborist allows attackers to write arbitrary files to any location on case-insensitive filesystems by exploiting case-se...

Aug 31, 2021
CVE-2025-10854
8.1

CVE-2025-10854 is a path traversal vulnerability in the txtai framework that allows arbitrary file write via malicious tar files containing symbolic l...

Sep 22, 2025
CVE-2025-66431
7.8

This vulnerability allows authenticated Plesk users with domain management permissions to execute arbitrary code with root privileges during domain cr...

Dec 3, 2025
CVE-2025-31133
7.8

This vulnerability in runc allows attackers to bypass container isolation by exploiting insufficient verification of bind-mount sources when using /de...

Nov 6, 2025
CVE-2025-36564
7.8

Dell Encryption Admin Utilities versions before 11.10.2 contain an improper link resolution vulnerability (CWE-61) that allows local malicious users t...

Jun 3, 2025
CVE-2024-47480
7.8

Dell Inventory Collector Client versions before 12.7.0 have a path traversal vulnerability where low-privilege local attackers can exploit improper li...

Dec 18, 2024
CVE-2021-25321
7.8

This CVE describes a local privilege escalation vulnerability in arpwatch on SUSE Linux systems. Attackers with control of the runtime user can create...

Jun 30, 2021
CVE-2020-15076
7.8

The Private Tunnel installer for macOS versions 3.0.1 and older contains a symlink vulnerability that allows attackers to corrupt critical system file...

May 26, 2021
CVE-2025-24886
7.7

This vulnerability allows authenticated users (admin privileges not required) to perform Local File Inclusion (LFI) attacks on pwn.college CTFd contai...

Jan 30, 2025
CVE-2026-25724
7.5

CVE-2026-25724 is a symbolic link bypass vulnerability in Claude Code that allows reading files explicitly denied in settings.json. Attackers could ac...

Feb 6, 2026
CVE-2025-52881
7.5

This CVE-2025-52881 vulnerability in runc allows attackers to redirect writes to /proc filesystem to other locations through race conditions with shar...

Nov 6, 2025
CVE-2025-52565
7.5

A vulnerability in runc allows attackers to bypass container isolation by tricking the system into bind-mounting sensitive read-only or masked paths t...

Nov 6, 2025
CVE-2021-32518
7.5

This vulnerability in QSAN Storage Manager's share_link function allows remote attackers to create symbolic links and access arbitrary files on the sy...

Jul 7, 2021
CVE-2023-41969
7.3

This vulnerability in ZSATrayManager allows unprivileged users to delete arbitrary files by exploiting inadequate protection of temporary encrypted ZA...

Mar 26, 2024
CVE-2026-23986
7.1

CVE-2026-23986 is a path traversal vulnerability in Copier project template tool that allows malicious templates to write files outside the intended d...

Jan 21, 2026
CVE-2024-1933
7.1

This vulnerability allows an attacker with unprivileged access to a macOS system running TeamViewer Remote Client to potentially elevate privileges or...

Mar 26, 2024
CVE-2025-54867
7.0

This vulnerability in Youki container runtime allows attackers to escape container isolation and access the host filesystem when /proc and /sys in the...

Aug 14, 2025
CVE-2025-22480
7.0

Dell SupportAssist OS Recovery versions before 5.5.13.1 contain a symbolic link attack vulnerability that allows local low-privileged attackers to del...

Feb 13, 2025
CVE-2025-3047
6.5

This vulnerability in AWS SAM CLI allows attackers to access privileged host files when building with Docker if symlinks are present in build files. T...

Mar 31, 2025
CVE-2024-52537
6.3

Dell Client Platform Firmware Update Utility has an Improper Link Resolution vulnerability (CWE-61) that allows a high-privileged attacker with local ...

Dec 11, 2024
CVE-2025-30485
6.2

A UNIX symbolic link following vulnerability in FutureNet NXR, VXR, and WXR series routers allows logged-in administrative users to access or destroy ...

Apr 3, 2025
CVE-2026-1386
6.0

A UNIX symbolic link following vulnerability in Firecracker's jailer component allows local host users with write access to pre-created jailer directo...

Jan 23, 2026
CVE-2024-25952
6.0

Dell PowerScale OneFS contains a UNIX symbolic link following vulnerability that allows local high-privileged attackers to manipulate symbolic links t...

Mar 28, 2024
CVE-2026-23968
5.5

This vulnerability in Copier allows safe templates to include arbitrary files/directories outside the local template clone location using symlinks wit...

Jan 21, 2026
CVE-2025-5468
5.5

This vulnerability allows authenticated local attackers to read arbitrary files on disk through improper symbolic link handling in Ivanti secure acces...

Aug 12, 2025
CVE-2024-34014
5.5

This vulnerability allows attackers to overwrite arbitrary files during recovery operations due to improper symbolic link handling in Acronis backup p...

Nov 11, 2024
CVE-2024-27872
5.5

This vulnerability allows a malicious app to bypass macOS symlink validation and access protected user data. It affects macOS systems before Sonoma 14...

Jul 29, 2024
CVE-2024-45418
5.4

This vulnerability in Zoom macOS installers allows authenticated users to escalate privileges via symlink attacks when network access is available. It...

Feb 25, 2025
CVE-2023-20091
5.1

This vulnerability allows authenticated local attackers with remote support accounts to overwrite arbitrary files on Cisco TelePresence CE and RoomOS ...

Nov 15, 2024
CVE-2024-42367
4.8

This vulnerability in aiohttp allows attackers to perform path traversal attacks when static routes contain compressed file variants (.gz or .br) that...

Aug 12, 2024
CVE-2025-64750
4.5

This vulnerability in SingularityCE and SingularityPRO container platforms allows attackers to bypass Linux Security Module (LSM) restrictions under s...

Dec 2, 2025
CVE-2025-65105
4.5

This vulnerability in Apptainer allows containers to bypass AppArmor and SELinux security restrictions when using the --security option. It affects un...

Dec 2, 2025
CVE-2026-27485
4.4

OpenClaw versions 2026.2.17 and below have a symlink vulnerability in the skill packaging script that allows local file inclusion when building .skill...

Feb 21, 2026
CVE-2024-52542
4.4

Dell AppSync version 4.6.0.x contains a symbolic link following vulnerability that allows local low-privileged attackers to tamper with files by manip...

Dec 17, 2024
CVE-2023-20093
4.4

This vulnerability allows authenticated local attackers with remote support accounts to overwrite arbitrary files on Cisco TelePresence CE and RoomOS ...

Nov 15, 2024
CVE-2025-62724
4.3

Open OnDemand HPC portal versions before 4.0.8 and 3.1.16 contain a TOCTOU vulnerability in zip file downloads that could allow authenticated users to...

Nov 20, 2025
CVE-2025-68937
N/A

This vulnerability in Forgejo allows attackers to write to unintended files through mishandling of symlink destinations in template repositories. Atta...

Dec 26, 2025
CVE-2025-53881
N/A

A UNIX symbolic link following vulnerability in logrotate configuration for the exim mail transfer agent allows local privilege escalation from mail u...

Oct 2, 2025

About CWE-61 (CWE-61)

Our database tracks 43 CVEs classified as CWE-61, with 2 rated critical and 21 rated high severity. The average CVSS score for CWE-61 vulnerabilities is 6.8.

External reference: View CWE-61 on MITRE CWE →

Monitor CWE-61 Vulnerabilities

Get alerted when new CWE-61 CVEs affect your infrastructure.

Start Monitoring Free