Intel

AIKIDO-2026-841016

uu_sort is vulnerable to Insecure Temporary File

Insecure Temporary File Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published 5 days ago

35

Low Risk

This Affects:

RUSTuu_sort
0.0.1 - 0.11.0
Fixed in 0.12.0
Are you affected? Scan for Free

TL;DR

sort created its merge temporary files and, for options that copy the input, its output-copy file without restricting their permissions, leaving them readable by other local users while they hold sort data that may include sensitive input contents. Another user on a shared system could read the temporary file's contents before it is removed. The fix creates these files with private (0600) permissions.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and other local users on the same system can read world-accessible temporary files.

Background info

uu_sort is vulnerable to Insecure Temporary File in versions 0.0.1 - 0.11.0.

How to fix this

Upgrade the uu_sort library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform