Insecure Temporary File Exposure in Bash Git Prompt by MagicMonty
CVE-2025-61659

6.8MEDIUM

Key Information:

Vendor

Magicmonty

Vendor
CVE Published:
29 September 2025

What is CVE-2025-61659?

The Bash Git Prompt versions 2.6.1 to 2.7.1 contain a vulnerability due to the insecure handling of temporary files. Specifically, the application creates a temporary file in the /tmp directory using a predictable naming convention. This predictable filename could be leveraged by an attacker to access sensitive information from the file, leading to potential unauthorized access and data exposure. Users of affected versions are encouraged to review their configurations and apply mitigations as necessary to secure their systems.

Affected Version(s)

bash-git-prompt 2.6.1 <= 2.7.1

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.