CWE-377— Insecure Temporary File
Creating and using insecure temporary files can leave application and system data vulnerable to attack.— MITRE CWE catalog
115 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-377page 3 of 3
- CVE-2021-28099MEDIUMCVSS 4.4EG 4.42021-03-23
In Netflix OSS Hollow, since the Files.exists(parent) is run before creating the directories, an attacker can pre-create these directories with wide permissions. Additionally, since an insecure source of randomness is used, the file names …
- CVE-2021-23331MEDIUMCVSS 4.4EG 4.42021-02-03
This affects all versions of package com.squareup:connect. The method prepareDownloadFilecreates creates a temporary file with the permissions bits of -rw-r--r-- on unix-like systems. On unix-like systems, the system temporary directory is…
- CVE-2026-55086MEDIUMCVSS 4.2EG 4.22026-08-13
Etherpad is a real-time collaborative editor. Prior to 3.1.0, src/node/handler/ImportHandler.ts and src/node/handler/ExportHandler.ts derive temporary filenames from Math.random() and place them in os.tmpdir(). On a host with a shared worl…
- CVE-2020-1994MEDIUMCVSS 4.1EG 4.12020-05-13
A predictable temporary file vulnerability in PAN-OS allows a local authenticated user with shell access to corrupt arbitrary system files affecting the integrity of the system. This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-O…
- CVE-2026-16791LOWCVSS 3.9EG 3.92026-08-04
A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite or truncate arbitrary local files with program-generated data when O…
- CVE-2015-0849LOWCVSS 3.9EG 3.92025-06-26
pycode-browser before version 1.0 is prone to a predictable temporary file vulnerability.
- CVE-2020-1740LOWCVSS 3.9EG 3.92020-03-16
A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes "ansible-vault edit", another user on the same computer can read the old and new secret, as it is created in a temporary file wit…
- CVE-2020-8030LOWCVSS 3.6EG 3.62021-02-11
A Insecure Temporary File vulnerability in skuba of SUSE CaaS Platform 4.5 allows local attackers to leak the bootstrapToken or modify the configuration file before it is processed, leading to arbitrary modifications of the machine/cluster.
- CVE-2026-35342LOWCVSS 3.3EG 3.32026-04-22
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid …
- CVE-2024-22236LOWCVSS 3.3EG 3.32024-01-31
In Spring Cloud Contract, versions 4.1.x prior to 4.1.1, versions 4.0.x prior to 4.0.5, and versions 3.1.x prior to 3.1.10, test execution is vulnerable to local information disclosure via temporary directory created with unsafe permission…
- CVE-2022-41954LOWCVSS 3.3EG 3.32022-11-25
MPXJ is an open source library to read and write project plans from a variety of file formats and databases. On Unix-like operating systems (not Windows or macos), MPXJ's use of `File.createTempFile(..)` results in temporary files being cr…
- CVE-2021-25316LOWCVSS 3.3EG 3.32021-04-14
A Insecure Temporary File vulnerability in s390-tools of SUSE Linux Enterprise Server 12-SP5, SUSE Linux Enterprise Server 15-SP2 allows local attackers to prevent VM live migrations This issue affects: SUSE Linux Enterprise Server 12-SP5 …
- CVE-2024-2313LOWCVSS 2.8EG 2.82024-03-10
If kernel headers need to be extracted, bpftrace will attempt to load them from a temporary directory. An unprivileged attacker could use this to force bcc to load compromised linux headers. Linux distributions which provide kernel headers…
- CVE-2022-3952LOWCVSS 2.6EG 2.62022-11-11
A vulnerability has been found in ManyDesigns Portofino 5.3.2 and classified as problematic. Affected by this vulnerability is the function createTempDir of the file WarFileLauncher.java. The manipulation leads to creation of temporary fil…
- CVE-2026-53759LOWCVSS 2.0EG 2.02026-07-06
linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to version 4.2.0, db_sqlite.py created SQLite databases at predictable paths in the shared /tmp directory and followed attac…
Map vulnerabilities like CWE-377 to your infrastructure
EchelonGraph correlates every CVE — across CWE-377 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →