GHSA-9gcf-pq99-rjw3Low

RPLY Predictable Tmpfile Names Allows Cache Spoofing

Published
May 17, 2022
Last Modified
May 29, 2026

🔗 CVE IDs covered (1)

📋 Description

The parser cache functionality in parsergenerator.py in RPLY (aka python-rply) before 0.7.1 allows local users to spoof cache data by pre-creating a temporary rply-*.json file with a predictable name.

🎯 Affected products1

  • pip/RPLY:< 0.7.1

🔗 References (9)