CVE-2026-45792: Rust Toctou File Re Read

Time-of-Check to Time-of-Use (TOCTOU) vulnerability. The file $PATH is validated but then re-read from disk. An attacker could modify the file between the check and the read, bypassing the validation. Return the verified content directly from the validation function instead of re-reading.

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0Rust
greprules fetch cve-2026-45792-rust-toctou-file-re-read --engine opengrep

Description

Time-of-Check to Time-of-Use (TOCTOU) vulnerability. The file $PATH is validated but then re-read from disk. An attacker could modify the file between the check and the read, bypassing the validation. Return the verified content directly from the validation function instead of re-reading.