CWE · MITRE source
CWE-59Improper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Last updated: 11 August 2026 21:18 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: partial · 2 mapping(s) from 2 framework(s): CAPEC 1 (partial) · ATT&CK 1 (partial)
OWASP Top 10 for Web (2025)
This weakness contributes to A01:2025 Broken Access Control.
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
NIST 800-53 r5 controls that address this weakness (0)AI-assisted
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
| No NIST controls proposed yet. | |||
MITRE ATT&CK techniques this weakness enables
Our own two-way CWE↔ATT&CK cross-walk — a direct mapping with no public source (the CWE→CAPEC→ATT&CK chain leaves most top weaknesses, incl. XSS and SQLi, mapped to nothing).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2015-1130 KEV UPD | 8.5 | 7.8 | 0.0989 | 2015-04-10 |
CVE-2019-0841 KEV UPD | 8.5 | 7.8 | 0.4140 | 2019-04-09 |
CVE-2019-1064 KEV UPD | 8.5 | 7.8 | 0.0689 | 2019-06-12 |
CVE-2019-1069 KEV UPD | 8.5 | 7.8 | 0.0612 | 2019-06-12 |
CVE-2019-1129 KEV UPD | 8.5 | 7.8 | 0.0178 | 2019-07-15 |
CVE-2019-1130 KEV UPD | 8.5 | 7.8 | 0.0228 | 2019-07-15 |
CVE-2019-1253 KEV UPD | 8.5 | 7.8 | 0.1162 | 2019-09-11 |
CVE-2019-1315 KEV UPD | 8.5 | 7.8 | 0.0348 | 2019-10-10 |
CVE-2019-1385 KEV UPD | 8.5 | 7.8 | 0.0362 | 2019-11-12 |
CVE-2020-0638 KEV UPD | 8.5 | 7.8 | 0.0304 | 2020-01-14 |
CVE-2020-0683 KEV UPD | 8.5 | 7.8 | 0.0767 | 2020-02-11 |
CVE-2020-0787 KEV UPD | 8.5 | 7.8 | 0.4252 | 2020-03-12 |
CVE-2020-36193 KEV UPD | 8.5 | 7.5 | 0.7059 | 2021-01-18 |
CVE-2022-21999 KEV UPD | 8.5 | 7.8 | 0.4168 | 2022-02-09 |
CVE-2022-30333 KEV UPD | 8.5 | 7.5 | 0.9911 | 2022-05-09 |
CVE-2023-36874 KEV UPD | 8.5 | 7.8 | 0.4341 | 2023-07-11 |
CVE-2025-60710 KEV UPD | 8.5 | 7.8 | 0.0460 | 2025-11-11 |
CVE-2026-41091 KEV UPD | 8.5 | 7.8 | 0.0964 | 2026-05-20 |
CVE-2021-21300 UPD | 8.3 | 8.0 | 0.8864 | 2021-03-09 |
CVE-2025-48384 KEV UPD | 8.3 | 8.0 | 0.0284 | 2025-07-08 |
CVE-2024-28185 UPD | 8.1 | 10.0 | 0.0706 | 2024-04-18 |
CVE-2024-28189 UPD | 8.1 | 10.0 | 0.0721 | 2024-04-18 |
CVE-2024-57728 KEV UPD | 8.1 | 7.2 | 0.0698 | 2025-01-15 |
CVE-2021-32610 UPD | 8.0 | 7.1 | 0.7338 | 2021-07-30 |
CVE-2025-21391 KEV UPD | 8.0 | 7.1 | 0.0226 | 2025-02-11 |