Cyber Resilience

CWE · MITRE source

CWE-59Improper Link Resolution Before File Access ('Link Following')

Abstraction: Base · CVEs in our corpus: 1,639

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Last updated: 11 August 2026 21:18 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: partial · 2 mapping(s) from 2 framework(s): CAPEC 1 (partial) · ATT&CK 1 (partial)

See the full cumulative-coverage rollup →

OWASP Top 10 for Web (2025)

This weakness contributes to A01:2025 Broken Access Control.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • PR.PS-06
  • AC-3 Access Enforcement
  • AC-6 Least Privilege
  • SC-4 Information in Shared System Resources
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V15.4.2

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

MITRE ATT&CK techniques this weakness enables

Our own two-way CWE↔ATT&CK cross-walk — a direct mapping with no public source (the CWE→CAPEC→ATT&CK chain leaves most top weaknesses, incl. XSS and SQLi, mapped to nothing).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2015-1130 KEV 8.57.80.09892015-04-10
CVE-2019-0841 KEV 8.57.80.41402019-04-09
CVE-2019-1064 KEV 8.57.80.06892019-06-12
CVE-2019-1069 KEV 8.57.80.06122019-06-12
CVE-2019-1129 KEV 8.57.80.01782019-07-15
CVE-2019-1130 KEV 8.57.80.02282019-07-15
CVE-2019-1253 KEV 8.57.80.11622019-09-11
CVE-2019-1315 KEV 8.57.80.03482019-10-10
CVE-2019-1385 KEV 8.57.80.03622019-11-12
CVE-2020-0638 KEV 8.57.80.03042020-01-14
CVE-2020-0683 KEV 8.57.80.07672020-02-11
CVE-2020-0787 KEV 8.57.80.42522020-03-12
CVE-2020-36193 KEV 8.57.50.70592021-01-18
CVE-2022-21999 KEV 8.57.80.41682022-02-09
CVE-2022-30333 KEV 8.57.50.99112022-05-09
CVE-2023-36874 KEV 8.57.80.43412023-07-11
CVE-2025-60710 KEV 8.57.80.04602025-11-11
CVE-2026-41091 KEV 8.57.80.09642026-05-20
CVE-2021-21300 8.38.00.88642021-03-09
CVE-2025-48384 KEV 8.38.00.02842025-07-08
CVE-2024-28185 8.110.00.07062024-04-18
CVE-2024-28189 8.110.00.07212024-04-18
CVE-2024-57728 KEV 8.17.20.06982025-01-15
CVE-2021-32610 8.07.10.73382021-07-30
CVE-2025-21391 KEV 8.07.10.02262025-02-11