AWS Security ChangesHomeSearch

AWS cli: Document --no-follow-symlinks behavior when downloading from S3

Service: cli · 2026-10-01 · Security-related medium

File: cli/latest/reference/s3/sync.md · Type: symlink

Summary

Expands the --follow-symlinks/--no-follow-symlinks description to state that on download, --no-follow-symlinks skips objects whose destination is a symlink or lies under one, while symlinks in the leading path are still followed.

Security assessment

Documents that --no-follow-symlinks prevents sync downloads from writing through symlinked destinations, a hardening behavior against symlink-based path traversal/overwrite; no CVE cited.

Evidence

+`--follow-symlinks` | `--no-follow-symlinks` (boolean) Symbolic links are followed when uploading to S3 from the local filesystem. Note that S3 does not support symbolic links, so the contents of the link target are uploaded under the name of the link. When downloading from S3, `--no-follow-symlinks` skips any object whose destination is a symbolic link, or is located under one, starting at the destination you specified. Symbolic links in the path leading up to that destination are still followed. When neither `--follow-symlinks` nor `--no-follow-symlinks` is specified, the default is to follow symlinks.

Diff

diff --git a/cli/latest/reference/s3/sync.md b/cli/latest/reference/s3/sync.md
index 65db07d..a29d0aa 100644
--- a//cli/latest/reference/s3/sync.md
+++ b//cli/latest/reference/s3/sync.md
@@ -15 +15 @@
-  * [AWS CLI 2.37.6 Command Reference](../../index.html) »
+  * [AWS CLI 2.37.7 Command Reference](../../index.html) »
@@ -142 +142 @@ Syncs directories and S3 prefixes. Recursively copies new and updated files from
-`--follow-symlinks` | `--no-follow-symlinks` (boolean) Symbolic links are followed only when uploading to S3 from the local filesystem. Note that S3 does not support symbolic links, so the contents of the link target are uploaded under the name of the link. When neither `--follow-symlinks` nor `--no-follow-symlinks` is specified, the default is to follow symlinks.
+`--follow-symlinks` | `--no-follow-symlinks` (boolean) Symbolic links are followed when uploading to S3 from the local filesystem. Note that S3 does not support symbolic links, so the contents of the link target are uploaded under the name of the link. When downloading from S3, `--no-follow-symlinks` skips any object whose destination is a symbolic link, or is located under one, starting at the destination you specified. Symbolic links in the path leading up to that destination are still followed. When neither `--follow-symlinks` nor `--no-follow-symlinks` is specified, the default is to follow symlinks.
@@ -527 +527 @@ Output:
-  * [AWS CLI 2.37.6 Command Reference](../../index.html) »
+  * [AWS CLI 2.37.7 Command Reference](../../index.html) »