CVE-2026-12345
CVE-2026-12345 — Race condition in tempfile.TemporaryDirectory cleanup allows deleting files outside the temporary directory
The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms.
Published Updated Sources: cvelistV5, PSF
Triage
Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.
Exploitation
Exploit code
public exploit, none observed
EPSS
0%
chance of exploitation in 30 days
CVSS base
5.9
MEDIUM
CISA SSVC assessment
Three decision points CISA publishes for the CVEs it assesses · SSVC 2.0.3. A stakeholder decision, not a severity score.
Exploitation
None
none · proof-of-concept · active
Automatable
No
can an attacker script all four kill-chain steps
Technical impact
Partial
partial · total control of the vulnerable component
Affected scope
The catalog records vendors and products as separate lists, not pairs, so which product belongs to which vendor is not something this page can say.
Vendors (1)
Products (1)
Every base score collected
Sources score independently and disagree; each row says who scored it and under which version.
| Score | Version | Severity | Expl. | Impact | Source |
|---|---|---|---|---|---|
| 5.9 | CVSS 4.0 | MEDIUM | — | — | cvelistV5 |
Weakness & attack patterns
- CWE-59
Attack patterns reported against this CVE. The ATT&CK techniques below are inferred from its weakness class.
- T1547.009Boot or Logon Autostart Execution: Shortcut Modification
- T1574.005Hijack Execution Flow: Executable Installer File Permissions Weakness
- T1574.010Hijack Execution Flow: Services File Permissions Weakness
Public exploit
Capability, not use: code existing is a different claim from anyone running it.
Indexed by
References
6 on the record
- github.com/python/cpython/pull/157580
patch
- github.com/python/cpython/issues/157579
issue-tracking
- github.com/python/cpython/commit/5c20517a4fc56683efe63a7751020db9573f538d
patch
- github.com/python/cpython/commit/458e7134a5af7f86aee9d21b51cf499b41aa4420
patch
- github.com/python/cpython/commit/e1f3590f155c6d66007e958c98c9d69316551993
patch
- www.openwall.com/lists/oss-security/2026/09/29/40
reference
Elsewhere on this site
- python software foundationevery CVE for this vendor
- CWE-59other pages naming this weakness
Not in any source we poll
Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.
- No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
- No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
- No exploit packet captures, log samples, or incident case IDs supplied.