Impact
The race condition, identified as a CWE-59 weakness, occurs during the cleanup of a TemporaryDirectory object in CPython's tempfile module. An attacker who can alter the directory tree while the cleanup routine is running may replace a real directory or file with a symbolic link pointing elsewhere. When the cleanup removes the TemporaryDirectory, it follows that symlink and deletes or changes metadata of files outside the intended temporary space. The result is unintended deletion or permission changes of arbitrary files owned by the process, which can corrupt data or disrupt services.
Affected Systems
CPython, the standard Python implementation maintained by the Python Software Foundation, is affected. All versions that have not yet incorporated the patch referenced in commit 5c20517a4fc56683efe63a7751020db9573f538d are vulnerable. The issue specifically involves the tempfile.TemporaryDirectory cleanup routine and the shutil.rmtree behavior that does not always prevent symlink attacks.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, and the EPSS score is not available, so the precise exploitation probability is uncertain. The vulnerability requires that an attacker be able to modify the target directory tree while the cleanup is executing, which typically means local execution or influence over the temporary directory content. Because the cleanup runs with the privileges of the Python process, the consequences can include unintended deletion of files that the process is allowed to modify. The absence of a KEV listing suggests no widespread exploitation yet.
OpenCVE Enrichment