When standard temporary directory validations fail, this code falls back to an alternative temporary directory without checking execution privileges. This may lead to local privilege escalation if the directory is accessible to lower privileged users and the application is running as SYSTEM.
Explore
Rule Explorer
Search the public rule index by CVE, GHSA, CWE, language, framework, author, or rule slug. Filter by language, framework, severity, confidence, license, and validation status.
- Public rules
- 2917
- Downloads
- 3.3M
- Verified
- 2917
- Authors
- 2
Search the rule indexUse CVE, GHSA, CWE, language, framework, package, or rule slug.
CVE-2026-42171: Nsis Insecure Temp Fallbackcve-2026-42171-nsis-insecure-temp-fallback
CVE-2025-55284: Insecure Tmp File Writecve-2025-55284-insecure-tmp-file-write
Writing to a hardcoded or predictable path in a world-writable directory (like /tmp/) can lead to local privilege escalation or file corruption via symlink attacks (CWE-379). Use the built-in `tempfile` module (e.g., `tempfile.NamedTemporaryFile` or `tempfile.mkstemp`) to create temporary files securely.
All matching rules loaded.