Intel

AIKIDO-2026-959375

common-io is vulnerable to Insecure Temporary File

Insecure Temporary File Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Yesterday

27

Low Risk

This Affects:

JAVAcommon-io
3.0 - 3.14.0
Fixed in 3.15.0
Are you affected? Scan for Free

TL;DR

FileCacheSeekableStream.createTempFile in common-io creates its on-disk image cache files with File.createTempFile, which honors the process umask and is typically world-readable. Any other local user on a shared or multi-user host can read cached image data while TwelveMonkeys caches a stream to disk. ImageIO readers that enable disk-based stream caching go through this path. The fix switches to Files.createTempFile, which creates the file with owner-only permissions.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and image reading uses on-disk stream caching on a shared or multi-user host.

Background info

common-io is vulnerable to Insecure Temporary File in versions 3.0 - 3.14.0.

How to fix this

Upgrade the common-io library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform