Insecure Temporary File Handling in CodexBar by steipete
CVE-2026-49135

7.2HIGH

Key Information:

Vendor

Steipete

Status
Vendor
CVE Published:
1 June 2026

What is CVE-2026-49135?

CodexBar versions before 0.32.0 are vulnerable to an insecure temporary file handling issue. Local attackers can exploit this vulnerability to gain unauthorized access to sensitive credentials, such as the App Store Connect API key, by manipulating predictable file paths in the release notarization workflow. This allows attackers with local access to the host to read sensitive information from fixed paths, create files or symbolic links in expected locations to redirect data to their own systems, or alter notarization archives prior to submission.

Affected Version(s)

CodexBar 0

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chia Min Jun Lennon
.