Medium severity6.8NVD Advisory· Published Sep 1, 2025· Updated Apr 22, 2026
CVE-2025-9810
CVE-2025-9810
Description
TOCTOU in linenoiseHistorySave in linenoise allows local attackers to overwrite arbitrary files and change permissions via a symlink race between fopen("w") on the history path and subsequent chmod() on the same path.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/antirez/linenoise/pull/202nvdIssue TrackingThird Party Advisory
- github.com/antirez/linenoise/blob/master/linenoise.cnvdProduct
- github.com/antirez/linenoise/blob/4111f1d6cd29e136b4e86a25d1dd859a1e00813b/linenoise.cnvd
- github.com/antirez/linenoise/commit/f2558e1e588b1ba384ec73a2cf5c9a46409753dbnvd
News mentions
0No linked articles in our index yet.