pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.
https://www.openwall.com/lists/oss-security/2026/01/21/5
https://github.com/pytest-dev/pytest/issues/13669
Source: Mitre, NVD
Published: 2026-01-22
Updated: 2026-01-26
Base Score: 4.6
Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:P
Severity: Medium
Base Score: 6.8
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
EPSS: 0.00004