Intel

AIKIDO-2026-112379

imageio-icns is vulnerable to Insecure Temporary File

Insecure Temporary File Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Yesterday

27

Low Risk

This Affects:

JAVAimageio-icns
3.0 - 3.14.0
Fixed in 3.15.0
Are you affected? Scan for Free

TL;DR

SipsJP2Reader.dumpToFile in the imageio-icns plugin also uses File.createTempFile to write a temporary PNG when decoding an ICNS image containing a JPEG2000 payload via the macOS sips tool, creating that file with default umask-based (typically world-readable) permissions. Any other local user on a shared host can read the dumped image data while the reader runs. The fix switches to Files.createTempFile, which restricts the file to owner-only permissions.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you decode ICNS images containing JPEG2000 data on macOS, where the reader shells out to sips, on a shared or multi-user host.

Background info

imageio-icns is vulnerable to Insecure Temporary File in versions 3.0 - 3.14.0.

How to fix this

Upgrade the com.twelvemonkeys.imageio:imageio-icns library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform