Home

Description

CodexBar prior to 0.32.0 contains an insecure temporary file handling vulnerability that allows local attackers to access sensitive credentials or tamper with build artifacts by exploiting predictable file paths in the release notarization workflow. Attackers with access to the same host can read the App Store Connect API key written to a fixed path, pre-create files or symbolic links at predictable locations to redirect writes to attacker-controlled destinations, or tamper with notarization archives before submission.

PUBLISHED Reserved 2026-05-27 | Published 2026-06-01 | Updated 2026-06-02 | Assigner VulnCheck




HIGH: 7.2CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

HIGH: 7.1CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Problem types

Insecure Temporary File

Improper Link Resolution Before File Access ('Link Following')

Product status

Default status
affected

Any version before 0.32.0
affected

Credits

Chia Min Jun Lennon finder

References

github.com/steipete/CodexBar/pull/1228 exploit

github.com/steipete/CodexBar/releases/tag/v0.32.0 release-notes

github.com/steipete/CodexBar/pull/1228 issue-tracking

github.com/...ommit/e7d932616508cee43ea9bcc63c269b14698de655 patch

www.vulncheck.com/...-file-handling-in-notarization-workflow third-party-advisory

cve.org (CVE-2026-49135)

nvd.nist.gov (CVE-2026-49135)

Download JSON