CWE · MITRE source
CWE-59Improper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Last updated: 26 September 2026 00:34 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: partial · 1 mapping(s) from 1 framework(s): ATT&CK 1 (partial)
OWASP Top 10 for Web (2025)
This weakness contributes to A01:2025 Broken Access Control.
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
NIST 800-53 r5 controls that address this weakness (0)AI-assisted
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
| No NIST controls proposed yet. | |||
MITRE ATT&CK techniques this weakness enables
Our own two-way CWE↔ATT&CK cross-walk — a direct mapping with no public source (the CWE→CAPEC→ATT&CK chain leaves most top weaknesses, incl. XSS and SQLi, mapped to nothing).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2015-1130 KEV UPD | 8.5 | 7.8 | 0.0989 | 2015-04-10 |
CVE-2015-5287 KEV UPD | 8.5 | 7.8 | 0.0496 | 2015-12-07 |
CVE-2019-0841 KEV UPD | 8.5 | 7.8 | 0.4140 | 2019-04-09 |
CVE-2019-1064 KEV UPD | 8.5 | 7.8 | 0.0689 | 2019-06-12 |
CVE-2019-1069 KEV UPD | 8.5 | 7.8 | 0.0612 | 2019-06-12 |
CVE-2019-1129 KEV UPD | 8.5 | 7.8 | 0.0178 | 2019-07-15 |
CVE-2019-1130 KEV UPD | 8.5 | 7.8 | 0.0170 | 2019-07-15 |
CVE-2019-1253 KEV UPD | 8.5 | 7.8 | 0.1162 | 2019-09-11 |
CVE-2019-1315 KEV UPD | 8.5 | 7.8 | 0.0348 | 2019-10-10 |
CVE-2019-1385 KEV UPD | 8.5 | 7.8 | 0.0360 | 2019-11-12 |
CVE-2020-0638 KEV UPD | 8.5 | 7.8 | 0.0235 | 2020-01-14 |
CVE-2020-0683 KEV UPD | 8.5 | 7.8 | 0.0761 | 2020-02-11 |
CVE-2020-0787 KEV UPD | 8.5 | 7.8 | 0.4252 | 2020-03-12 |
CVE-2020-36193 KEV UPD | 8.5 | 7.5 | 0.7059 | 2021-01-18 |
CVE-2022-21999 KEV UPD | 8.5 | 7.8 | 0.4101 | 2022-02-09 |
CVE-2022-30333 KEV UPD | 8.5 | 7.5 | 0.9909 | 2022-05-09 |
CVE-2023-36874 KEV UPD | 8.5 | 7.8 | 0.4341 | 2023-07-11 |
CVE-2025-60710 KEV UPD | 8.5 | 7.8 | 0.0460 | 2025-11-11 |
CVE-2026-41091 KEV UPD | 8.5 | 7.8 | 0.0044 | 2026-05-20 |
CVE-2026-81963 KEV | 8.5 | 7.8 | 0.0039 | 2026-09-08 |
CVE-2021-21300 UPD | 8.3 | 8.0 | 0.8853 | 2021-03-09 |
CVE-2025-48384 KEV UPD | 8.3 | 8.0 | 0.0411 | 2025-07-08 |
CVE-2024-28185 UPD | 8.1 | 10.0 | 0.0706 | 2024-04-18 |
CVE-2024-28189 UPD | 8.1 | 10.0 | 0.0721 | 2024-04-18 |
CVE-2024-57728 KEV UPD | 8.1 | 7.2 | 0.6466 | 2025-01-15 |