Race Condition Vulnerability in Temporary Directory Cleanup of Python by Python Software Foundation
CVE-2026-12345
5.9MEDIUM
What is CVE-2026-12345?
A race condition vulnerability exists in the cleanup process of tempfile.TemporaryDirectory in Python. This flaw allows attackers with the ability to modify the directory tree during cleanup to replace a legitimate temporary directory with a symbolic link. As a result, files located outside of the intended temporary directory may be inadvertently deleted or have their permissions and flags altered, presenting significant security risks. Systems where specific symlink attack protections are not enforced remain vulnerable, potentially leading to further unintended exposure.
Affected Version(s)
CPython 0 < 3.15.0
References
CVSS V4
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Bitshift (https://github.com/TheShiftedBit)
Stan Ulbrych (https://github.com/StanFromIreland)
Petr Viktorin (https://github.com/encukou)
