Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-12345— Race condition in tempfile.TemporaryDirectory cleanup allows deleting files outside the temporary directory

Quick assessment

Affected
Python Software Foundation CPython
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

的清理过程存在竞态条件漏洞。攻击者若在清理过程中能够修改目录树,便可以用符号链接替换某个目录,从而导致临时目录外部的文件被删除,或其权限和文件标志位(file flags)被重置,且这些操作将以执行清理进程的权限身份进行。需要注意的是,对于 属性为 false 的平台,该漏洞依然受影响;此外,在所有平台上,目录树之外的文件标志位仍可能被重置。

CVSS 5.9 · Medium EPSS 0.18% · P7

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 2

VendorProduct Version RangeStatus
Python Software Foundation CPython < 3.12.15 affected
3.13.0a1< 3.15.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-12345

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Race condition in tempfile.TemporaryDirectory cleanup allows deleting files outside the temporary directory
Source: CVE Program / CVE List V5
Vulnerability Description
The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Python Software Foundation CPython 0 ~ 3.12.15 -

II. Public POCs for CVE-2026-12345

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-12345

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-12345 (5)

Other References for CVE-2026-12345 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-12345

No comments yet


Leave a comment