CVE Vulnerabilities

CVE-2025-71176

Creation of Temporary File in Directory with Insecure Permissions

Published: Jan 22, 2026 | Modified: Jan 26, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.8 MODERATE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.

Weakness

The product creates a temporary file in a directory whose permissions allow unintended actors to determine the file’s existence or otherwise access that file.

Potential Mitigations

References