VYPR

CWE-377

Insecure Temporary File

ClassIncomplete

Description

Creating and using insecure temporary files can leave application and system data vulnerable to attack.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-149 · CAPEC-155

CVEs mapped to this weakness (128)

page 4 of 7
  • CVE-2023-49344MedDec 14, 2023
    risk 0.39cvss 6.0epss 0.00

    Temporary data passed between application components by Budgie Extras Window Shuffler applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may pre-create and control this…

  • CVE-2023-49342MedDec 14, 2023
    risk 0.39cvss 6.0epss 0.00

    Temporary data passed between application components by Budgie Extras Clockworks applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may pre-create and control this file…

  • CVE-2023-33695HigJun 13, 2023
    risk 0.39cvss 7.1epss 0.00

    Hutool v5.8.17 and below was discovered to contain an information disclosure vulnerability via the File.createTempFile() function at /core/io/FileUtil.java.

  • CVE-2026-46406MedJun 29, 2026
    risk 0.37cvss 6.1epss 0.00

    Claude Code is an agentic coding tool. From 2.1.59 until 2.1.128, the Claude Code /copy command wrote responses to a hardcoded, predictable path (/tmp/claude/response.md) without UID isolation, randomness, or symlink protection. The file was created world-readable (0644) in a…

  • CVE-2026-20618MedFeb 11, 2026
    risk 0.36cvss 5.5epss 0.00

    An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Tahoe 26.3. An app may be able to access user-sensitive data.

  • CVE-2024-23287MedMar 8, 2024
    risk 0.36cvss 5.5epss 0.01

    A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. An app may be able to access user-sensitive data.

  • CVE-2022-35631MedJul 29, 2022
    risk 0.36cvss 5.5epss 0.00

    On MacOS and Linux, it may be possible to perform a symlink attack by replacing this predictable file name with a symlink to another file and have the Velociraptor client overwrite the other file. This issue was resolved in Velociraptor 0.6.5-2.

  • CVE-2021-28100MedMar 23, 2021
    risk 0.36cvss 5.5epss 0.00

    Priam uses File.createTempFile, which gives the permissions on that file -rw-r--r--. An attacker with read access to the local filesystem can read anything written there by the Priam process.

  • CVE-2017-7560MedSep 13, 2017
    risk 0.36cvss 5.5epss 0.00

    It was found that rhnsd PID files are created as world-writable that allows local attackers to fill the disks or to kill selected processes.

  • CVE-2026-40635MedSep 9, 2026
    risk 0.35cvss 5.4epss 0.00

    Dell PowerScale OneFS versions 9.12.0.0 through 9.13.1.0 contain an Insecure Temporary File vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to denial of service and information tampering.

  • CVE-2025-14602MedAug 20, 2026
    risk 0.34cvss —epss 0.00

    The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to accurately guess or brute-force the generated filename within a short time window. An attacker can successfully locate and access…

  • CVE-2026-75920MedAug 19, 2026
    risk 0.34cvss 5.3epss 0.00

    phpMyFAQ before v4.1.6 writes content backup ZIP archives to the web-accessible document root at content.zip, exposing sensitive files including database credentials. Unauthenticated attackers can race concurrent requests to download the temporary ZIP file before deletion, or…

  • CVE-2018-25068MedJan 6, 2023
    risk 0.34cvss 6.3epss 0.01

    A vulnerability has been found in devent globalpom-utils up to 4.5.0 and classified as critical. This vulnerability affects the function createTmpDir of the file globalpomutils-fileresources/src/main/java/com/anrisoftware/globalpom/fileresourcemanager/FileResourceManagerProvider.…

  • CVE-2021-3702MedAug 23, 2022
    risk 0.34cvss 6.3epss 0.00

    A race condition flaw was found in ansible-runner, where an attacker could watch for rapid creation and deletion of a temporary directory, substitute their directory at that name, and then have access to ansible-runner's private_data_dir the next time ansible-runner made use of…

  • CVE-2024-34490MedMay 5, 2024
    risk 0.33cvss 5.1epss 0.00

    In Maxima through 5.47.0 before 51704c, the plotting facilities make use of predictable names under /tmp. Thus, the contents may be controlled by a local attacker who can create files in advance with these names. This affects, for example, plot2d.

  • CVE-2022-21945MedMar 16, 2022
    risk 0.33cvss 5.1epss 0.00

    A Insecure Temporary File vulnerability in cscreen of openSUSE Factory allows local attackers to cause DoS for cscreen and a system DoS for non-default systems. This issue affects: openSUSE Factory cscreen version 1.2-1.3 and prior versions.

  • CVE-2021-46705MedMar 16, 2022
    risk 0.33cvss 5.1epss 0.00

    A Insecure Temporary File vulnerability in grub-once of grub2 in SUSE Linux Enterprise Server 15 SP4, openSUSE Factory allows local attackers to truncate arbitrary files. This issue affects: SUSE Linux Enterprise Server 15 SP4 grub2 versions prior to 2.06-150400.7.1. SUSE…

  • CVE-2026-41991MedJun 29, 2026
    risk 0.31cvss 4.7epss 0.00

    GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable…

  • CVE-2020-35451MedMar 9, 2021
    risk 0.31cvss 4.7epss 0.00

    There is a race condition in OozieSharelibCLI in Apache Oozie before version 5.2.1 which allows a malicious attacker to replace the files in Oozie's sharelib during it's creation.

  • CVE-2025-9474MedAug 26, 2025
    risk 0.29cvss 4.5epss 0.00

    A vulnerability was detected in Mihomo Party up to 1.8.1 on macOS. Affected is the function enableSysProxy of the file src/main/sys/sysproxy.ts of the component Socket Handler. The manipulation results in creation of temporary file with insecure permissions. The attack requires…