CVE-2025-61659Medium· 6.8▾ Sunlitbash-git-prompt 2.6.1 through 2.7.1 insecurely uses the /tmp/git-index-private$$ file, which has a predictable name.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 37.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
bash-git-prompt 2.6.1 through 2.7.1 insecurely uses the /tmp/git-index-private$$ file, which has a predictable name.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2021-29429Medium· 4.0In Gradle before version 7.0, files created with open permissions in the system temporary directory can allow an attacker to access information downloaded by Gradle
CVE-2026-106451High· 7.3yawkat LZ4 Java provides LZ4 compression for Java
CVE-2026-79899High· 7.9Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert
CVE-2025-14602NoneThe application generates uploaded file names using a weak and predictable method based on the request timestamp
CVE-2026-54584Medium· 5.3mport is the MidnightBSD Package Manager
CVE-2026-40635Medium· 5.4Dell PowerScale OneFS versions 9.12.0.0 through 9.13.1.0 contain an Insecure Temporary File vulnerability