VYPR

garminconnect

by Garminconnect

CVEs (1)

  • CVE-2026-54447higJul 15, 2026
    risk 0.45cvss epss

    ## Insecure Permission Assignment for Garmin OAuth Token Store ### Summary `garminconnect` (≤ 0.3.4) wrote its OAuth token store to disk without restricting file-system permissions. Under the default Linux umask (`022`) the token file `garmin_tokens.json` was created…