AWS Security ChangesHomeSearch

AWS cli: Document --no-follow-symlinks behavior when downloading from S3

Service: cli · 2026-10-01 · Security-related medium

File: cli/latest/reference/s3/cp.md · Type: symlink

Summary

Expands the --follow-symlinks/--no-follow-symlinks description to state that on download, --no-follow-symlinks skips objects whose destination is a symlink or lies under one, while symlinks in the leading path are still followed.

Security assessment

The new text documents that --no-follow-symlinks prevents writing downloaded objects through a symlink at or below the destination, which mitigates symlink-based arbitrary file overwrite/path-traversal during S3 downloads; this is a concrete hardening behavior, though no CVE is cited.

Evidence

+`--follow-symlinks` | `--no-follow-symlinks` (boolean) Symbolic links are followed when uploading to S3 from the local filesystem. Note that S3 does not support symbolic links, so the contents of the link target are uploaded under the name of the link. When downloading from S3, `--no-follow-symlinks` skips any object whose destination is a symbolic link, or is located under one, starting at the destination you specified. Symbolic links in the path leading up to that destination are still followed. When neither `--follow-symlinks` nor `--no-follow-symlinks` is specified, the default is to follow symlinks.

Diff

diff --git a/cli/latest/reference/s3/cp.md b/cli/latest/reference/s3/cp.md
index d6b1e07..976f057 100644
--- a//cli/latest/reference/s3/cp.md
+++ b//cli/latest/reference/s3/cp.md
@@ -15 +15 @@
-  * [AWS CLI 2.37.6 Command Reference](../../index.html) »
+  * [AWS CLI 2.37.7 Command Reference](../../index.html) »
@@ -141 +141 @@ Copies a local file or S3 object to another location locally or in S3.
-`--follow-symlinks` | `--no-follow-symlinks` (boolean) Symbolic links are followed only when uploading to S3 from the local filesystem. Note that S3 does not support symbolic links, so the contents of the link target are uploaded under the name of the link. When neither `--follow-symlinks` nor `--no-follow-symlinks` is specified, the default is to follow symlinks.
+`--follow-symlinks` | `--no-follow-symlinks` (boolean) Symbolic links are followed when uploading to S3 from the local filesystem. Note that S3 does not support symbolic links, so the contents of the link target are uploaded under the name of the link. When downloading from S3, `--no-follow-symlinks` skips any object whose destination is a symbolic link, or is located under one, starting at the destination you specified. Symbolic links in the path leading up to that destination are still followed. When neither `--follow-symlinks` nor `--no-follow-symlinks` is specified, the default is to follow symlinks.
@@ -656 +656 @@ Output:
-  * [AWS CLI 2.37.6 Command Reference](../../index.html) »
+  * [AWS CLI 2.37.7 Command Reference](../../index.html) »