CVE-2023-2800: Python Insecure Tempfile Mktemp

Use of `tempfile.mktemp()` followed by `open()` on the returned path is insecure (CWE-377 / CVE-2023-2800). `mktemp()` only predicts a filename without atomically creating the file, opening a TOCTOU race in which a local attacker can place a symlink at the predicted path before it is opened, leading to arbitrary file overwrite. Replace this pattern with `tem

Provally CuratedPublic repositoryMediumHigh confidenceVerifiedApache-2.0Python
greprules fetch cve-2023-2800-python-insecure-tempfile-mktemp --engine opengrep

Description

Use of `tempfile.mktemp()` followed by `open()` on the returned path is insecure (CWE-377 / CVE-2023-2800). `mktemp()` only predicts a filename without atomically creating the file, opening a TOCTOU race in which a local attacker can place a symlink at the predicted path before it is opened, leading to arbitrary file overwrite. Replace this pattern with `tem