Insecure Temporary File Creation in AutoExtract Component of Robocode
CVE-2025-14307

9.3CRITICAL

Key Information:

Status
Vendor
CVE Published:
9 December 2025

What is CVE-2025-14307?

The AutoExtract component of Robocode version 1.9.3.6 is susceptible to an insecure temporary file creation flaw. This vulnerability arises from the createTempFile method failing to securely generate temporary files. By exploiting race conditions, an attacker could potentially execute arbitrary code or overwrite critical files on the system. Manipulation of the temporary file creation process allows unauthorized actions, making it essential for users to address this vulnerability promptly to secure their installations.

Affected Version(s)

Robocode Windows 1.9.3.6

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

.