Home
MEDIUM: 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:LDefault status
unknown
Any version
affected
Description
pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.
Problem types
CWE-379 Creation of Temporary File in Directory with Insecure Permissions
Product status
Any version
References
github.com/pytest-dev/pytest/issues/13669
www.openwall.com/lists/oss-security/2026/01/21/5