CVE-2026-62294

MEDIUM

Flameshot: OCTOU symlink attack via predictable /tmp path in Flameshot "Open With"

Title source: cna
STIX 2.1

Description

Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to a predictable temporary path and followed symlinks, creating a time-of-check to time-of-use race that allowed a local unprivileged attacker on the same machine to pre-plant a symlink and cause Flameshot to write PNG data through it, overwriting any file the victim user could write. This issue is fixed in version 14.0.0.

Scores

CVSS v4 5.1
EPSS 0.0010
EPSS Percentile 1.1%
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-362 CWE-377
Status published
Products (1)
flameshot-org/flameshot < 14.0.0
Published Jul 15, 2026
Tracked Since Jul 15, 2026