CVE-2026-12345

medium

Description

The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms.

References

https://github.com/TolgaHanGunler/kernel-cve-runbook

https://github.com/Otyg/cveRisk

https://github.com/Diwahar555/CVE-Vulnerability-Tracker

https://github.com/moto-timo/kcve

https://github.com/eduolihez/kev-digest

https://github.com/jim-lahey69/snow-cve-risk-framework

https://github.com/logiover/cve-security-advisory-monitor

https://github.com/LacunaAporia/cve-correlation-engine

https://github.com/phaasma/cveinsight

https://github.com/sureshkumark03/Threat-Intelligence-Correlation-Engine

https://github.com/gcve-eu/gcve-eu-ai-extension

https://github.com/black-hak/feedmind

https://github.com/NullAILab/nullai-security-news

https://github.com/Hiroki-Tomimatsu/cve-monitor

https://github.com/x0x7b/ThreatFeed

https://github.com/cybernexuslabs-research/ThreatPulse

https://github.com/CPAN-Security/cna-tool

https://github.com/grokify/structured-changelog

https://github.com/joupify/soc-cert-guardian-extension

https://github.com/python/cpython/pull/157580

https://github.com/python/cpython/issues/157579

https://github.com/python/cpython/commit/e1f3590f155c6d66007e958c98c9d69316551993

https://github.com/python/cpython/commit/5c20517a4fc56683efe63a7751020db9573f538d

https://github.com/python/cpython/commit/458e7134a5af7f86aee9d21b51cf499b41aa4420

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-89183

http://www.openwall.com/lists/oss-security/2026/09/29/40

Details

Source: Mitre, NVD

Published: 2026-09-29

Updated: 2026-09-30

Risk Information

CVSS v2

Base Score: 5.4

Vector: CVSS2#AV:L/AC:M/Au:N/C:N/I:P/A:C

Severity: Medium

CVSS v3

Base Score: 6.7

Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

Severity: Medium

CVSS v4

Base Score: 5.9

Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

Severity: Medium

EPSS

EPSS: 0.0018