Impact
Il ya-lact contains a vulnerability where it creates predictable temporary files in /tmp. An attacker with local file system access can create a symbolic link pointing to an arbitrary path before LACT writes to that temporary file. The application then follows the symlink, overwriting or deleting unintended files, which can lead to a local denial‑of‑service by corrupting the application state. The weakness is described by CWE‑61.
Affected Systems
The issue affects the LACT project maintained by ilya‑zlobintsev. All releases up through version 0.10.0 are impacted. Users of these versions should consider upgrading to a later release that removes the predictable temp file handling.
Risk and Exploitability
The CVSS score is 6.9, indicating a moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires local access to the system that hosts the application, and no network‑based exploitation is described. Because the vulnerability can cause service disruption through file corruption, it represents a moderate risk to availability for systems running unpatched LACT.
OpenCVE Enrichment