Impact
garminconnect is a Python 3 API wrapper for Garmin Connect that retrieves statistics and manages activities. Prior to version 0.3.5, garmin OAuth token directory and garmin_tokens.json without explicit owner‑only modes, so a permissive umask such as 022 can leave the directory mode at 0755 and the token file mode at 0644. garmin and another Linux or macOS host can read the token and obtain persistent access to the victim’s Garmin Connect account, including health, fitness, activity, and device data. The Garmin.login tokenstore path is affected, and a pre‑existing loosely permissioned token file remains exposed until rewritten or manually restricted. This issue is fixed in version 0.3.5, but legacy installations without the fix still risk token leakage.
Affected Systems
Python‑based applications that use the cyberjunky:python‑garminconnect package with a version older than 0.3.5. The vulnerability is present when Client.dump creates or reads the Garmin.login tokenstore path. Any shared Unix‑style host where users can coexist with the application process is affected.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity of the vulnerability, and the EPSS score is < 1% indicating a very low likelihood of exploitation based on current data. The attack vector is local: an attacker must be able to run code on the same machine to read the token file. The vulnerability is not listed in CISA’s KEV catalog, but the potential for sensitive data breach is significant. Exploitation requires only reading a file that falls outside of strict permissions, which is trivial once the attacker has local access.
OpenCVE Enrichment
Github GHSA