PULSE
LIVE35signals / 24h
FEED
ransomglobal secret group reclama a West Nova Fuels & Superline Fuels · CA · Energy & Utilitiesransomglobal secret group reclama a Sinop Energia · BR · Energy & Utilitiesransomglobal secret group reclama a Al Hayat | Pepsi · IQ · Retail & E-Commerceransomglobal secret group reclama a SPDM · BR · Healthcareransomglobal secret group reclama a Nourison | Home · US · Retail & E-Commerceransomglobal secret group reclama a Cold Front Distribution · US · Retail & E-Commerceransomglobal secret group reclama a Portman Finance Group · GB · Financial Servicesransomglobal secret group reclama a OFS · US · Manufacturingransomglobal secret group reclama a Uniview Technologies · CN · Technologyransomglobal secret group reclama a Novum Energy · US · Energy & Utilitiesransomdragonforce reclama a Syntron Bioresearch · US · Healthcareransomdragonforce reclama a Deluxe Medical Supply · US · Healthcareransomchaos reclama a remco.ca · CA · Otherransomqilin reclama a Contacto Garantido · MX · Professional Servicesransomglobal secret group reclama a West Nova Fuels & Superline Fuels · CA · Energy & Utilitiesransomglobal secret group reclama a Sinop Energia · BR · Energy & Utilitiesransomglobal secret group reclama a Al Hayat | Pepsi · IQ · Retail & E-Commerceransomglobal secret group reclama a SPDM · BR · Healthcareransomglobal secret group reclama a Nourison | Home · US · Retail & E-Commerceransomglobal secret group reclama a Cold Front Distribution · US · Retail & E-Commerceransomglobal secret group reclama a Portman Finance Group · GB · Financial Servicesransomglobal secret group reclama a OFS · US · Manufacturingransomglobal secret group reclama a Uniview Technologies · CN · Technologyransomglobal secret group reclama a Novum Energy · US · Energy & Utilitiesransomdragonforce reclama a Syntron Bioresearch · US · Healthcareransomdragonforce reclama a Deluxe Medical Supply · US · Healthcareransomchaos reclama a remco.ca · CA · Otherransomqilin reclama a Contacto Garantido · MX · Professional Services
← All CVEs
CVE WatchJul 23, 2026

CVE-2026-65010

Datasets through 5.00, fixed in commit ad2d853, contains a symlink-following vulnerability in Extractor.extract() that allows local attacker

CVSS

6.6

Medium

EPSS

0.1%

p3

KEV

Exploit Today

1

0-100

Published: Jul 23, 2026 · Last modified: Jul 23, 2026 · CWE-61

EPSS · 30d
0.1%EPSS · 30 days0.1%
2026-07-242026-07-25
Technical description

Datasets through 5.00, fixed in commit ad2d853, contains a symlink-following vulnerability in Extractor.extract() that allows local attackers to write arbitrary files by pre-planting symlinks at predictable output paths. Attackers can redirect archive extraction to arbitrary filesystem locations in shared-cache environments, enabling overwrite of sensitive files and potential privilege escalation or code execution.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-174594.3 MED
0A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.externalLocation of the file src/main/java/spark/resource/ExternalResourceHandler.jav of the component SparkJava. Executing a manipulation can lead to symlink following. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.7h
CVE-2026-120807.3 HIG
3.7%
1A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-add-authorized-keys command handler by manipulating symbolic links. This can occur either through a deterministic directory-symlink bypass or a Time-of-Check to Time-of-Use (TOCTOU) file-symlink race. Successful exploitation allows the attacker to gain ownership of arbitrary root-owned files or directories, leading to root access. This vulnerability requires an external management layer (e.g., libvirt) to trigger the affected code path.5d
CVE-2026-59674
3.0%
1A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed suricata package allows the suricata user to escalate to root. This issue affects openSUSE Tumbleweed: from ? before 8.0.5-2.1; openSUSE Tumbleweed: from ? before 8.0.5-2.1.11d
CVE-2026-398227.8 HIG
14.3%
4On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.13d
CVE-2026-146993.3 LOW
3.8%
1A weakness has been identified in zcaceres markdownify-mcp up to 1.1.0. The affected element is the function assertPathAllowed of the file src/Markdownify.ts. Executing a manipulation can lead to symlink following. The attack can only be executed locally. The pull request to fix this issue awaits acceptance.20d
CVE-2026-534896.5 MED
8.5%
3containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a bug where the CRI plugin restores container.log from a checkpoint image without validating a symlinked path. This could result in reading an arbitrary file on the host via kubectl logs. This issue has been fixed in versions 2.3.2, 2.2.5 and 2.1.9.24d