CWE-377: Insecure Temporary File
Creating and using insecure temporary files can leave application and system data vulnerable to attack.
91 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-14307 — Insecure Temporary File Creation in Robocode's AutoExtract Component
- CVE-2025-46369 — Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contains an Insecure Temporary File vulnerability
- CVE-2026-4822 — Enter Software Iperius Backup Backup Service temp file
- CVE-2024-49506 — Fixed temporary file path in aeon-checks allows fixing of disk encryption key
- CVE-2025-7707 — World-Writable NLTK Cache Directory Vulnerability in run-llama/llama_index
- CVE-2025-34194 — Vasion Print (formerly PrinterLogic) Local Privilege Escalation via Insecure Temporary File Handling
- CVE-2025-61659 — bash-git-prompt 2.6.1 through 2.7.1 insecurely uses the /tmp/git-index-private$$ file, which has a predictable name.
- CVE-2025-14614 — Quartus® Prime Standard and Quartus® Prime Lite Security Advisory
- CVE-2025-14612 — Quartus Prime Pro Edition Advisory
- CVE-2025-46368 — Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contains an Insecure Temporary File vulnerability
- CVE-2026-49134 — CodexBar < 0.32.0 Privilege Escalation via CLI Installer Temp File
- CVE-2026-63404 — Faktory: Insecure predictable /tmp/redis.conf enables local Redis config hijack (network exposure / root RCE primitive)
- CVE-2026-49135 — CodexBar < 0.32.0 Insecure Temporary File Handling in Notarization Workflow
- CVE-2026-20204 — Improper Handling and Insufficient Isolation of Specific Temporary Files in Splunk Enterprise
- CVE-2026-40973 — A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTe
- CVE-2026-73585 — Sblim-cmpi-base: insecure temporary file creation in sblim-cmpi-base provider registration scripts allows local symlink attack
- CVE-2026-73584 — Sblim-sfcb: sblim-sfcb: privileged file corruption and denial of service via insecure temporary file handling
- CVE-2026-45384 — bit7z: Arbitrary File Overwrite via Symlink Attack on Predictable Temp File During Archive Update
- CVE-2026-40979 — In Spring AI, having access to a shared environment can expose the ONNX model used by the application. Affected version
- CVE-2026-75920 — phpMyFAQ before 4.1.6 Information Disclosure via Backup ZIP
Recently published
- CVE-2026-40635 — Dell PowerScale OneFS versions 9.12.0.0 through 9.13.1.0 contain an Insecure Temporary File vulnerability. A low privile
- CVE-2026-63404 — Faktory: Insecure predictable /tmp/redis.conf enables local Redis config hijack (network exposure / root RCE primitive)
- CVE-2025-14602 — Weak File Name Generation in vsDesk
- CVE-2026-55086 — Etherpad: Import/export use Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwrite
- CVE-2026-75920 — phpMyFAQ before 4.1.6 Information Disclosure via Backup ZIP
- CVE-2026-53759 — linuxfabrik-lib: Insecure creation of SQLite databases
- CVE-2026-73584 — Sblim-sfcb: sblim-sfcb: privileged file corruption and denial of service via insecure temporary file handling
- CVE-2026-73585 — Sblim-cmpi-base: insecure temporary file creation in sblim-cmpi-base provider registration scripts allows local symlink attack
- CVE-2026-16791 — Predictable Temporary File Symlink Vulnerability in Lenovo XClarity Essentials OneCLI
- CVE-2026-62294 — Flameshot: OCTOU symlink attack via predictable /tmp path in Flameshot "Open With"
- CVE-2026-46406 — Claude Code: Insecure Temporary File in /copy Command Enables Response Disclosure and Symlink-Based File Write
- CVE-2026-41001 — Predictable Temp Directory in Artemis Auto-configuration
- CVE-2026-45384 — bit7z: Arbitrary File Overwrite via Symlink Attack on Predictable Temp File During Archive Update
- CVE-2026-49135 — CodexBar < 0.32.0 Insecure Temporary File Handling in Notarization Workflow
- CVE-2026-49134 — CodexBar < 0.32.0 Privilege Escalation via CLI Installer Temp File
- CVE-2026-40979 — In Spring AI, having access to a shared environment can expose the ONNX model used by the application. Affected version
- CVE-2026-40973 — A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTe
- CVE-2026-35342 — uutils coreutils mktemp Insecure Temporary File Placement via Empty TMPDIR
- CVE-2026-20204 — Improper Handling and Insufficient Isolation of Specific Temporary Files in Splunk Enterprise
- CVE-2026-4822 — Enter Software Iperius Backup Backup Service temp file