VYPR

CodexBar

by Steipete

Source repositories

CVEs (2)

  • CVE-2026-49135HigJun 1, 2026
    risk 0.39cvss 7.1epss

    CodexBar prior to 0.32.0 contains an insecure temporary file handling vulnerability that allows local attackers to access sensitive credentials or tamper with build artifacts by exploiting predictable file paths in the release notarization workflow. Attackers with access to the…

  • CVE-2026-49134HigJun 1, 2026
    risk 0.39cvss 7.1epss

    CodexBar prior to 0.32.0 contains a privilege escalation vulnerability in the CLI installer that allows local attackers to execute arbitrary commands as root by exploiting a race condition in temporary file handling. The installer creates a temporary file with mktemp, writes a…