CVE-2026-12345
Received Received - Intake

Race Condition in Python's tempfile.TemporaryDirectory Cleanup

Vulnerability report for CVE-2026-12345, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Python Software Foundation

Description

The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 8 associated CPEs
Vendor Product Version / Range
python python 3.10
python python 3.11
python python 3.12
python python 3.13
python python 3.14
python python 3.15
python python 3.16
python python *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-59 The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a race condition in Python's tempfile.TemporaryDirectory cleanup process. An attacker can replace a directory with a symbolic link during cleanup, causing files outside the temporary directory to be deleted or have permissions/file flags reset. This affects platforms where shutil.rmtree.avoids_symlink_attacks is false.

Detection Guidance

To detect this vulnerability, check if your Python version is affected (3.10 through 3.16). Run 'python --version' to verify. Inspect applications using tempfile.TemporaryDirectory for unusual file deletions or permission changes during cleanup.

Impact Analysis

An attacker could exploit this to delete important files outside the temporary directory or alter their permissions. This could lead to data loss, system instability, or unauthorized access to sensitive files, depending on the privileges of the process performing cleanup.

Compliance Impact

This vulnerability could lead to unauthorized file deletion or permission changes, potentially violating data integrity and confidentiality requirements in GDPR and HIPAA. Compliance may be impacted if sensitive data is exposed or altered due to the race condition.

Mitigation Strategies

Update Python to a patched version (3.10+ with fixes). If unable to update, avoid using tempfile.TemporaryDirectory in untrusted environments or implement custom cleanup logic that avoids race conditions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12345. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart