CWE-377— Insecure Temporary File
Creating and using insecure temporary files can leave application and system data vulnerable to attack.— MITRE CWE catalog
115 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-377page 2 of 3
- CVE-2025-14612MEDIUMCVSS 6.7EG 6.72026-01-07
Insecure Temporary File vulnerability in Altera Quartus Prime Pro Installer (SFX) on Windows allows : Use of Predictable File Names.This issue affects Quartus Prime Pro: from 24.1 through 25.1.1.
- CVE-2024-5742MEDIUMCVSS 6.7EG 6.72024-06-12
A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a…
- CVE-2020-8032MEDIUMCVSS 6.7EG 6.72021-02-25
A Insecure Temporary File vulnerability in the packaging of cyrus-sasl of openSUSE Factory allows local attackers to escalate to root. This issue affects: openSUSE Factory cyrus-sasl version 2.1.27-4.2 and prior versions.
- CVE-2025-46368MEDIUMCVSS 6.6EG 6.62025-11-13
Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contains an Insecure Temporary File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tamp…
- CVE-2020-25636MEDIUMCVSS 6.6EG 6.62020-10-05
A flaw was found in Ansible Base when using the aws_ssm connection plugin as there is no namespace separation for file transfers. Files are written directly to the root bucket, making possible to have collisions when running multiple ansib…
- CVE-2022-26386MEDIUMCVSS 6.5EG 6.52022-12-22
Previously Firefox for macOS and Linux would download temporary files to a user-specific directory in <code>/tmp</code>, but this behavior was changed to download them to <code>/tmp</code> where they could be affected by other local users.…
- CVE-2017-20147MEDIUMCVSS 6.5EG 6.52022-09-20
In the ebuild package through smokeping-2.7.3-r1 for SmokePing on Gentoo, the initscript uses a PID file that is writable by the smokeping user. By writing arbitrary PIDs to that file, the smokeping user can cause a denial of service to ar…
- CVE-2017-16024MEDIUMCVSS 6.5EG 6.52018-06-04
The sync-exec module is used to simulate child_process.execSync in node versions <0.11.9. Sync-exec uses tmp directories as a buffer before returning values. Other users on the server have read access to the tmp directory, possibly allowin…
- CVE-2017-7549MEDIUMCVSS 6.4EG 6.42017-09-21
A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy script…
- CVE-2026-73584MEDIUMCVSS 6.3EG 6.32026-08-13
A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the `/tmp` directory. By repeatedly recreating a symbolic link, the atta…
- CVE-2026-73585MEDIUMCVSS 6.3EG 6.32026-08-13
A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a local unprivileged user to perform a symlink attack. By creating a symlink in a world-writable directory, an attacker can r…
- CVE-2018-25068MEDIUMCVSS 6.3EG 6.32023-01-06
A vulnerability has been found in devent globalpom-utils up to 4.5.0 and classified as critical. This vulnerability affects the function createTmpDir of the file globalpomutils-fileresources/src/main/java/com/anrisoftware/globalpom/fileres…
- CVE-2026-20651MEDIUMCVSS 6.2EG 6.22026-03-25
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to access sensitive user data.
- CVE-2021-28100MEDIUMCVSS 5.5EG 6.22021-03-23
Priam uses File.createTempFile, which gives the permissions on that file -rw-r--r--. An attacker with read access to the local filesystem can read anything written there by the Priam process.
- CVE-2026-46406MEDIUMCVSS 6.1EG 6.12026-06-25
Claude Code is an agentic coding tool. From 2.1.59 until 2.1.128, the Claude Code /copy command wrote responses to a hardcoded, predictable path (/tmp/claude/response.md) without UID isolation, randomness, or symlink protection. The file …
- CVE-2026-45384MEDIUMCVSS 6.1EG 6.12026-06-10
bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4.0.12, there is an arbitrary file overwrite vulnerability via symlink attack on predictable temp files during archive u…
- CVE-2026-40979MEDIUMCVSS 6.1EG 6.12026-04-28
In Spring AI, having access to a shared environment can expose the ONNX model used by the application. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5)
- CVE-2026-25645MEDIUMCVSS 5.5EG 5.52026-03-25
Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file a…
- CVE-2026-20618MEDIUMCVSS 5.5EG 5.52026-02-11
An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Tahoe 26.3. An app may be able to access user-sensitive data.
- CVE-2024-23287MEDIUMCVSS 5.5EG 5.52024-03-08
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. An app may be able to access user-sensitive data.
- CVE-2022-24913MEDIUMCVSS 5.5EG 5.52023-01-12
Versions of the package com.fasterxml.util:java-merge-sort before 1.1.0 are vulnerable to Insecure Temporary File in the StdTempFileProvider() function in StdTempFileProvider.java, which uses the permissive File.createTempFile() function, …
- CVE-2022-35631MEDIUMCVSS 5.5EG 5.52022-07-29
On MacOS and Linux, it may be possible to perform a symlink attack by replacing this predictable file name with a symlink to another file and have the Velociraptor client overwrite the other file. This issue was resolved in Velociraptor 0.…
- CVE-2021-22572MEDIUMCVSS 5.5EG 5.52022-03-29
On unix-like systems, the system temporary directory is shared between all users on that system. The root cause is File.createTempFile creates files in the the system temporary directory with world readable permissions. Any sensitive infor…
- CVE-2021-29429MEDIUMCVSS 5.5EG 5.52021-04-12
In Gradle before version 7.0, files created with open permissions in the system temporary directory can allow an attacker to access information downloaded by Gradle. Some builds could be vulnerable to a local information disclosure. Remote…
- CVE-2017-15111MEDIUMCVSS 5.5EG 5.52018-01-20
keycloak-httpd-client-install versions before 0.8 insecurely creates temporary file allowing local attackers to overwrite other files via symbolic link.
- CVE-2017-7560MEDIUMCVSS 5.5EG 5.52017-09-13
It was found that rhnsd PID files are created as world-writable that allows local attackers to fill the disks or to kill selected processes.
- CVE-2022-21945MEDIUMCVSS 5.1EG 5.52022-03-16
A Insecure Temporary File vulnerability in cscreen of openSUSE Factory allows local attackers to cause DoS for cscreen and a system DoS for non-default systems. This issue affects: openSUSE Factory cscreen version 1.2-1.3 and prior version…
- CVE-2021-46705MEDIUMCVSS 5.1EG 5.52022-03-16
A Insecure Temporary File vulnerability in grub-once of grub2 in SUSE Linux Enterprise Server 15 SP4, openSUSE Factory allows local attackers to truncate arbitrary files. This issue affects: SUSE Linux Enterprise Server 15 SP4 grub2 versio…
- CVE-2018-19640MEDIUMCVSS 4.4EG 5.52019-03-05
If the attacker manages to create files in the directory used to collect log files in supportutils before version 3.1-5.7.1 (e.g. with CVE-2018-19638) he can kill arbitrary processes on the local machine.
- CVE-2018-19637MEDIUMCVSS 2.8EG 5.52019-03-05
Supportutils, before version 3.1-5.7.1, wrote data to static file /tmp/supp_log, allowing local attackers to overwrite files on systems without symlink protection
- CVE-2022-3969MEDIUMCVSS 2.6EG 5.52022-11-13
A vulnerability was found in OpenKM up to 6.3.11 and classified as problematic. Affected by this issue is the function getFileExtension of the file src/main/java/com/openkm/util/FileUtils.java. The manipulation leads to insecure temporary …
- CVE-2022-4641MEDIUMCVSS 2.5EG 5.52022-12-21
A vulnerability was found in pig-vector and classified as problematic. Affected by this issue is the function LogisticRegression of the file src/main/java/org/apache/mahout/pig/LogisticRegression.java. The manipulation leads to insecure te…
- CVE-2018-17955MEDIUMCVSS 2.2EG 5.52019-03-15
In yast2-multipath before version 4.1.1 a static temporary filename allows local attackers to overwrite files on systems without symlink protection
- CVE-2026-40635MEDIUMCVSS 5.4EG 5.42026-09-09
Dell PowerScale OneFS versions 9.12.0.0 through 9.13.1.0 contain an Insecure Temporary File vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to denial of service and information tamperin…
- CVE-2026-54584MEDIUMCVSS 5.3EG 5.32026-09-21
mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including when running as root or in setuid/setgid contexts. An attacker able to control the environment for a privileged mport in…
- CVE-2025-14602MEDIUMCVSS 5.3EG 5.32026-08-20
The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to accurately guess or brute-force the generated filename within a short time window. An attac…
- CVE-2026-75920MEDIUMCVSS 5.3EG 5.32026-08-19
phpMyFAQ before v4.1.6 writes content backup ZIP archives to the web-accessible document root at content.zip, exposing sensitive files including database credentials. Unauthenticated attackers can race concurrent requests to download the t…
- CVE-2026-41001MEDIUMCVSS 5.3EG 5.32026-06-11
Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured. A local attacker on the same host can pre-create this predictable dir…
- CVE-2026-62294MEDIUMCVSS 5.1EG 5.12026-07-15
Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to a predictable temporary path and followed symlinks, creating a time-of-check to time-of-use race that allowed a local …
- CVE-2024-34490MEDIUMCVSS 5.1EG 5.12024-05-05
In Maxima through 5.47.0 before 51704c, the plotting facilities make use of predictable names under /tmp. Thus, the contents may be controlled by a local attacker who can create files in advance with these names. This affects, for example,…
- CVE-2020-10744MEDIUMCVSS 5.0EG 5.02020-05-15
An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the race condition on systems using ACLs an…
- CVE-2020-1733MEDIUMCVSS 5.0EG 5.02020-03-11
A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is …
- CVE-2025-66625MEDIUMCVSS 4.9EG 4.92025-12-09
Umbraco is an ASP.NET CMS. Due to unsafe handling and deletion of temporary files in versions 10.0.0 through 13.12.0, during the dictionary upload process an attacker with access to the backoffice can trigger predictable requests to tempor…
- CVE-2026-41991MEDIUMCVSS 4.7EG 4.72026-06-29
GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the p…
- CVE-2023-2800MEDIUMCVSS 4.7EG 4.72023-05-18
Insecure Temporary File in GitHub repository huggingface/transformers prior to 4.30.0.
- CVE-2022-41946MEDIUMCVSS 4.7EG 4.72022-11-23
pgjdbc is an open source postgresql JDBC Driver. In affected versions a prepared statement using either `PreparedStatement.setText(int, InputStream)` or `PreparedStatemet.setBytea(int, InputStream)` will create a temporary file if the Inpu…
- CVE-2020-35451MEDIUMCVSS 4.7EG 4.72021-03-09
There is a race condition in OozieSharelibCLI in Apache Oozie before version 5.2.1 which allows a malicious attacker to replace the files in Oozie's sharelib during it's creation.
- CVE-2018-19638MEDIUMCVSS 2.2EG 4.72019-03-05
In supportutils, before version 3.1-5.7.1 and if pacemaker is installed on the system, an unprivileged user could have overwritten arbitrary files in the directory that is used by supportutils to collect the log files.
- CVE-2025-9474MEDIUMCVSS 4.5EG 4.52025-08-26
A vulnerability was detected in Mihomo Party up to 1.8.1 on macOS. Affected is the function enableSysProxy of the file src/main/sys/sysproxy.ts of the component Socket Handler. The manipulation results in creation of temporary file with in…
- CVE-2024-10372MEDIUMCVSS 4.5EG 4.52024-10-25
A vulnerability classified as problematic was found in chidiwilliams buzz 1.1.0. This vulnerability affects the function download_model of the file buzz/model_loader.py. The manipulation leads to insecure temporary file. It is possible to …
Map vulnerabilities like CWE-377 to your infrastructure
EchelonGraph correlates every CVE — across CWE-377 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →