USENIX Security2026Top-tier venue
Wormholes in the File System: Understanding the Misunderstanding of Symlinks
Yongheng Liu, Lei Zhang, Yuhang Zhao, Yuzhou He
Abstract
Symlinks, a file system feature supported at the operating system level for more than four decades, are deeply integrated across the software stack, making them an indispensable component of modern computing environments. The symlink mechanism is highly flexible, allowing references to nearly any location in the file system and enabling complex resolution behaviors. However, this flexibility also introduces significant misunderstandings for developers, which has led to widespread misuse and become a primary vector for critical security vulnerabilities in file-handling software, e.g., arbitrary file write and code execution.
In this paper, we present the first systematic study of how symlinks are incorrectly handled and the substantial security risks. Specifically, we study how programming language standard libraries improperly utilize symlink-related system calls, and how such misuse and misunderstanding propagates to downstream applications which results in various inadequate path validations. To further understand whether these inadequate path validations could be exploited in real world, we design and implement five path validation bypass schemes and three arbitrary write methods. Our evaluation across 85 projects uncovered 16 arbitrary file write vulnerabilities, two of which have been assigned high-severity CVEs. We also demonstrate their severe impacts in real-world scenarios and propose multiple mitigation strategies. We have responsibly disclosed these issues to the affected vendors.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 035d37da-31bc-4a96-b66d-2af7be727329Builds on10
- Small World with High Risks: A Study of Security Threats in the npm EcosystemMarkus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, Michael PradelUSENIX Security 2019 · 281 citations
- Didn't You Hear Me? - Towards More Successful Web Vulnerability NotificationsBen Stock, Giancarlo Pellegrino, Frank Li, Michael Backes et al.NDSS 2018 · 86 citations
- Lost along the Way: Understanding and Mitigating Path-Misresolution Threats to Container IsolationZhi Li, Weijie Liu, XiaoFeng Wang, Bin Yuan et al.CCS 2023 · 6 citations
- On the Abuse and Detection of Polyglot FilesLuke Koch, Sean Oesch, Amir Sadovnik, Brian Weber et al.WWW 2025
- Be Aware of What You Let Pass: Demystifying URL-based Authentication Bypass Vulnerability in Java Web ApplicationsQiyi Zhang, Fengyu Liu, Zihan Lin, Yuan ZhangCCS 2025
Related papers
- Pig in a Poke: Automatically Detecting and Exploiting Link Following Vulnerabilities in Windows File OperationsBocheng Xiang, Yuan Zhang, Fengyu Liu, Hao Huang et al.USENIX Security 2025
- Windows plays Jenga: Uncovering Design Weaknesses in Windows File System SecurityDong-uk Kim, JunYoung Park, Sanghak Oh, Hyoungshick Kim et al.CCS 2025
- File Hijacking Vulnerability: The Elephant in the RoomChendong Yu, Yang Xiao, Jie Lu, Yuekang Li et al.NDSS 2024
- SoK: Take a Deep Step into Linux Kernel Hardening Effectiveness from the Offensive-Defensive PerspectiveYinhao Hu, Pengyu Ding, Zhenpeng Lin, Dongliang Mu et al.NDSS 2026 · 3 citations
- Bilingual Problems: Studying the Security Risks Incurred by Native Extensions in Scripting LanguagesCristian-Alexandru Staicu, Sazzadur Rahaman, Ágnes Kiss, Michael BackesUSENIX Security 2023
