CWE-377— Insecure Temporary File
Creating and using insecure temporary files can leave application and system data vulnerable to attack.— MITRE CWE catalog
115 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-377page 1 of 3
- CVE-2011-4119CRITICALCVSS 9.8EG 9.82021-10-26
caml-light <= 0.75 uses mktemp() insecurely, and also does unsafe things in /tmp during make install.
- CVE-2012-2666CRITICALCVSS 9.8EG 9.82021-07-09
golang/go in 1.0.2 fixes all.bash on shared machines. dotest() in src/pkg/debug/gosym/pclntab_test.go creates a temporary file with predicable name and executes it as shell script.
- CVE-2015-5224CRITICALCVSS 9.8EG 9.82017-08-23
The mkostemp function in login-utils in util-linux when used incorrectly allows remote attackers to cause file name collision and possibly other attacks.
- CVE-2013-4561CRITICALCVSS 9.1EG 9.12022-06-30
In a openshift node, there is a cron job to update mcollective facts that mishandles a temporary file. This may lead to loss of confidentiality and integrity.
- CVE-2018-16494HIGHCVSS 8.8EG 8.82021-05-26
In VOS and overly permissive "umask" may allow for authorized users of the server to gain unauthorized access through insecure file permissions that can result in an arbitrary read, write, or execution of newly created files and directorie…
- CVE-2025-34194HIGHCVSS 8.5EG 8.52025-09-19
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application versions prior to 25.1.1413 (Windows client deployments) contain an insecure temporary-file handling vulnerability in the PrinterInstal…
- CVE-2023-34119HIGHCVSS 8.2EG 8.22023-07-11
Insecure temporary file in the installer for Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.
- CVE-2025-14307HIGHCVSS 8.1EG 8.12025-12-09
An insecure temporary file creation vulnerability exists in the AutoExtract component of Robocode version 1.9.3.6. The createTempFile method fails to securely create temporary files, allowing attackers to exploit race conditions and potent…
- CVE-2023-43498HIGHCVSS 8.1EG 8.12023-09-20
In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using MultipartFormDataParser creates temporary files in the default system temporary directory with the default permissions for newly created files, potentiall…
- CVE-2022-21809HIGHCVSS 8.1EG 8.12022-05-12
A file write vulnerability exists in the httpd upload.cgi functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can upload a malicious file to trigger this vuln…
- CVE-2026-79899HIGHCVSS 7.9EG 7.92026-10-01
Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under BO…
- CVE-2025-46369HIGHCVSS 7.8EG 7.82025-11-13
Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contains an Insecure Temporary File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escala…
- CVE-2025-7707HIGHCVSS 7.8EG 7.82025-10-13
The llama_index library version 0.12.33 sets the NLTK data directory to a subdirectory of the codebase by default, which is world-writable in multi-user environments. This configuration allows local users to overwrite, delete, or corrupt N…
- CVE-2023-49347HIGHCVSS 7.8EG 7.82023-12-14
Temporary data passed between application components by Budgie Extras Windows Previews could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attacker…
- CVE-2023-49346HIGHCVSS 7.8EG 7.82023-12-14
Temporary data passed between application components by Budgie Extras WeatherShow applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attack…
- CVE-2023-49345HIGHCVSS 7.8EG 7.82023-12-14
Temporary data passed between application components by Budgie Extras Takeabreak applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attacke…
- CVE-2023-49344HIGHCVSS 7.8EG 7.82023-12-14
Temporary data passed between application components by Budgie Extras Window Shuffler applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. At…
- CVE-2023-49342HIGHCVSS 7.8EG 7.82023-12-14
Temporary data passed between application components by Budgie Extras Clockworks applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attacke…
- CVE-2020-1991HIGHCVSS 7.8EG 7.82020-04-08
An insecure temporary file vulnerability in Palo Alto Networks Traps allows a local authenticated Windows user to escalate privileges or overwrite system files. This issue affects Palo Alto Networks Traps 5.0 versions before 5.0.8; 6.1 ver…
- CVE-2018-6705HIGHCVSS 7.8EG 7.82018-12-12
Privilege escalation vulnerability in McAfee Agent (MA) for Linux 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local users to perform arbitrary command execution via specific conditions.
- CVE-2018-6704HIGHCVSS 7.8EG 7.82018-12-12
Privilege escalation vulnerability in McAfee Agent (MA) for Linux 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local users to perform arbitrary command execution via specific conditions.
- CVE-2018-3710HIGHCVSS 7.8EG 7.82018-03-21
Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resulting remote code execution.
- CVE-2022-34387HIGHCVSS 6.4EG 7.82023-02-11
Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain a privilege escalation vulnerability. A local authenticated malicious user could potentially exploit this v…
- CVE-2022-4817HIGHCVSS 3.1EG 7.82022-12-28
A vulnerability was found in centic9 jgit-cookbook. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to insecure temporary file. The attack can be initiated remotely. The name of the patc…
- CVE-2026-47852HIGHCVSS 7.5EG 7.52026-08-26
A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9
- CVE-2025-67223HIGHCVSS 7.5EG 7.52026-04-28
The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs with predictable names in a publicly accessible directory, which allows unauthenticated remote attackers to obtain direc…
- CVE-2026-20649HIGHCVSS 7.5EG 7.52026-02-11
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, watchOS 26.3. A user may be able to view sensitive user information.
- CVE-2013-4253HIGHCVSS 7.5EG 7.52022-10-19
The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a default public key in the root user's authorized_keys file.
- CVE-2022-0315HIGHCVSS 7.5EG 7.52022-03-24
Insecure Temporary File in GitHub repository horovod/horovod prior to 0.24.0.
- CVE-2022-0736HIGHCVSS 7.5EG 7.52022-02-23
Insecure Temporary File in GitHub repository mlflow/mlflow prior to 1.23.1.
- CVE-2018-6706HIGHCVSS 7.5EG 7.52018-12-12
Insecure handling of temporary files in non-Windows McAfee Agent 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows an Unprivileged User to introduce custom paths during agent installation in Linux via unspecified vectors.
- CVE-2026-106451HIGHCVSS 7.3EG 7.32026-10-06
yawkat LZ4 Java provides LZ4 compression for Java. From 1.7.0 until 1.11.4, net.jpountz.util.Native.load() uses File.createTempFile to create an exclusive temporary .lck file but derives the native-library path by removing the suffix, then…
- CVE-2026-63404HIGHCVSS 7.3EG 7.32026-08-25
Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the embedded Redis bootstrapper is vulnerable to an insecure temporary file flaw that lets a local unprivileged user hijack the Redis configuration and esca…
- CVE-2024-49506HIGHCVSS 7.3EG 7.32024-11-13
Insecure creation of temporary files allows local users on systems with non-default configurations to cause denial of service or set the encryption key for a filesystem
- CVE-2021-20202HIGHCVSS 7.3EG 7.32021-05-12
A flaw was found in keycloak. Directories can be created prior to the Java process creating them in the temporary directory, but with wider user permissions, allowing the attacker to have access to the contents that keycloak stores in this…
- CVE-2020-8027HIGHCVSS 7.3EG 7.32021-02-11
A Insecure Temporary File vulnerability in openldap2 of SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Leap 15.2 allows local attackers to overwrite arbitrary files and gain acce…
- CVE-2016-9595HIGHCVSS 7.3EG 7.32018-07-27
A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary …
- CVE-2026-44878HIGHCVSS 7.2EG 7.22026-07-21
A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated remote attacker to access the device's filesystem. Successful exploitation of this vulnerability could allow an attacker…
- CVE-2026-49135HIGHCVSS 7.1EG 7.12026-06-01
CodexBar prior to 0.32.0 contains an insecure temporary file handling vulnerability that allows local attackers to access sensitive credentials or tamper with build artifacts by exploiting predictable file paths in the release notarization…
- CVE-2026-49134HIGHCVSS 7.1EG 7.12026-06-01
CodexBar prior to 0.32.0 contains a privilege escalation vulnerability in the CLI installer that allows local attackers to execute arbitrary commands as root by exploiting a race condition in temporary file handling. The installer creates …
- CVE-2026-20204HIGHCVSS 7.1EG 7.12026-04-15
In Splunk Enterprise versions below 10.2.1, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.5, 10.2.2510.9, 10.1.2507.19, 10.0.2503.13, and 9.3.2411.127, a low-privileged user that does not hold …
- CVE-2026-40973HIGHCVSS 7.0EG 7.02026-04-28
A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.servlet.session.persistent` is set to `true` and the attack persists across application restarts, thi…
- CVE-2026-4822HIGHCVSS 7.0EG 7.02026-03-25
A vulnerability was detected in Enter Software Iperius Backup up to 8.7.3. Affected is an unknown function of the file C:\ProgramData\IperiusBackup\Jobs\ of the component Backup Service. Performing a manipulation results in creation of tem…
- CVE-2026-25701HIGHCVSS 7.0EG 7.02026-02-25
An Insecure Temporary File vulnerability in openSUSE sdbootutil allows local users to pre-create a directory to achieve various effects like: * gain access to possible private information found in /var/lib/pcrlock.d * manipulate the…
- CVE-2020-2016HIGHCVSS 7.0EG 7.02020-05-13
A race condition due to insecure creation of a file in a temporary directory vulnerability in PAN-OS allows for root privilege escalation from a limited linux user account. This allows an attacker who has escaped the restricted shell as a …
- CVE-2020-1981HIGHCVSS 7.0EG 7.02020-03-11
A predictable temporary filename vulnerability in PAN-OS allows local privilege escalation. This issue allows a local attacker who bypassed the restricted shell to execute commands as a low privileged user and gain root access on the PAN-O…
- CVE-2018-1053HIGHCVSS 7.0EG 7.02018-02-09
In postgresql 9.3.x before 9.3.21, 9.4.x before 9.4.16, 9.5.x before 9.5.11, 9.6.x before 9.6.7 and 10.x before 10.2, pg_upgrade creates file in current working directory containing the output of `pg_dumpall -g` under umask which was in ef…
- CVE-2025-61659MEDIUMCVSS 6.8EG 6.82025-09-29
bash-git-prompt 2.6.1 through 2.7.1 insecurely uses the /tmp/git-index-private$$ file, which has a predictable name.
- CVE-2024-6654MEDIUMCVSS 6.8EG 6.82024-09-27
Products for macOS enables a user logged on to the system to perform a denial-of-service attack, which could be misused to disable the protection of the ESET security product and cause general system slow-down.
- CVE-2025-14614MEDIUMCVSS 6.7EG 6.72026-01-07
Insecure Temporary File vulnerability in Altera Quartus Prime Standard Installer (SFX) on Windows, Altera Quartus Prime Lite Installer (SFX) on Windows allows Explore for Predictable Temporary File Names.This issue affects Quartu…
Map vulnerabilities like CWE-377 to your infrastructure
EchelonGraph correlates every CVE — across CWE-377 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →