CVE-2026-28684: Tempfile Cross Device Symlink Overwritecve-2026-28684-tempfile-cross-device-symlink-overwrite
Creating a temporary file without specifying a `dir` and then moving it with `shutil.move` can lead to an arbitrary file overwrite. If the temporary directory is on a different filesystem than the destination, `shutil.move` falls back to a copy operation, which insecurely follows symbolic links at the destination path. Provide the `dir` argument so the tempo