CVE-2026-44705

Aliases:GHSA-ph9p-34f9-6g65DEBIAN-CVE-2026-44705CGA-2849-gjj9-rrcrCGA-295h-px5r-8442CGA-298h-49xg-xjwwCGA-2pcf-xcf8-x7rwCGA-2rrr-mqw9-m496CGA-37j9-qvfp-7fcvCGA-3c54-63w5-9wj7CGA-3fmh-p43g-g4hpCGA-3hc5-84rj-88gqCGA-43h2-x4j2-mvqfCGA-48jf-v422-rw73CGA-4q4g-7jfc-w4vqCGA-4rw4-953q-49q3CGA-5m66-2v5w-7jcpCGA-5wg9-jmrc-xx4jCGA-644x-x53q-85j4CGA-66gr-jmrv-c8m8CGA-6f8f-3fvh-7j5cCGA-6fwq-c43c-9fwqCGA-6jc5-57r2-f2gfCGA-6qf3-vpqv-4p48CGA-6rcj-58v8-jpwxCGA-73vv-v65p-f966CGA-77r4-33gg-q9hwCGA-794m-7q8m-vqf5CGA-7cq2-r5r8-f48hCGA-83jp-5jmf-h7g3CGA-84m7-fh3w-qh24CGA-8883-pcvx-398jCGA-88w4-r7w6-8jr3CGA-8crp-pq59-9mq3CGA-8mqg-29wc-7m59CGA-92pv-6cvw-6hg8CGA-986j-g3w6-vgwxCGA-98fv-qfv2-hvx3CGA-9hgr-mw34-7q9rCGA-9p79-8f3x-2xp5CGA-9vc5-8969-cm4gCGA-9w3h-8gq6-4j8hCGA-c7wr-7wgw-gcj4CGA-cxr7-6vr5-7wq5CGA-fg9x-f773-33m7CGA-fgjm-6x9p-j9xgCGA-fmr4-r228-73p7CGA-g6wv-38ww-fx69CGA-g862-hjm3-jq94CGA-g87r-ff4h-859xCGA-g963-798g-m5fgCGA-gpp8-pgf5-xq9qCGA-gq22-72q5-jprjCGA-gv73-jc8c-793wCGA-h737-fq67-mr2hCGA-hg97-9w2c-qp26CGA-hh35-fw69-q9v7CGA-hj6x-6pc9-q5g4CGA-hqm5-rpqx-3x4vCGA-j36h-qmv5-3258CGA-j3mr-xgv3-p26gCGA-j6c6-rwxj-xg7vCGA-j6qj-jgvm-2q32CGA-jjhp-qx5c-mx4pCGA-jpwp-h65f-42m7CGA-jqhw-xwg7-rj85CGA-jvph-hxx6-5hm5CGA-m3v5-g3j7-457wCGA-m43g-h9wg-73j2CGA-m6p2-m9mm-3r32CGA-m725-47g8-fq4qCGA-mhwm-7254-vxxjCGA-mj2m-x2vj-j2p5CGA-mm64-93pv-fxmrCGA-mmp7-c59h-xp97CGA-mmrf-r6fv-mwcgCGA-mqhw-59p7-7hpwCGA-mw38-r2vq-qvrfCGA-p348-g4m3-5x54CGA-p8px-v28r-jv49CGA-pp45-wggq-57xxCGA-25mx-w2fx-rc4wCGA-2774-4r47-w6c3CGA-29p9-vvpx-7j3jCGA-35j9-h3q2-63xqCGA-3759-cf3r-36vqCGA-378x-3972-g5fmCGA-392j-hwqf-hpg3CGA-395c-wv4v-q68rCGA-3rfx-29cw-v6g5CGA-3xg8-qr6v-qvqjCGA-4354-7qc2-8p6hCGA-479m-74xc-2vg6CGA-48jj-j5h8-pqwpCGA-493q-6w7r-wx7rCGA-4g96-gjcw-6v4pCGA-4vvh-353x-qjq4CGA-522p-gv7h-fjh6CGA-55vg-4qj5-c8c5CGA-56qc-qcgq-jg5hCGA-576c-hxm6-qvvqCGA-5f78-wr2v-vcg9CGA-5fm8-h4x2-ggg3CGA-5g9w-w4v6-c46wCGA-5jf6-69wc-vx6wCGA-5jwj-px9v-7cw5CGA-5mch-vhv7-mff5CGA-5vv8-g9cv-rq35CGA-5w6c-mfqg-fhr4CGA-5xff-m6pw-3rxpCGA-6768-hfwf-frj8CGA-6cg6-f98h-j77jCGA-6jf5-vppm-7xqrCGA-6whc-c75h-qcxvCGA-778q-grgj-v7w8CGA-7878-qgm9-qg3gCGA-7j9c-8hm8-3f4fCGA-7pw9-vm7v-wf8wCGA-7w5g-38gg-235rCGA-7w6x-5xmq-wjcvCGA-7xfw-fq85-73j4CGA-823m-pgw6-fc93CGA-856p-rc64-rw9gCGA-88hq-32mw-grp8CGA-89x6-745r-8g96CGA-8gqm-8w9r-g8xqCGA-8gw7-p863-9847CGA-8gx9-4w3c-7rgrCGA-8p5j-95v8-vhvvCGA-8rg9-558g-wr9rCGA-8vp4-m334-6fhqCGA-8vvh-xr9p-r8g8CGA-8w2r-27wj-jxh3CGA-99cj-47mv-7v74CGA-9f49-2qm8-xfj4CGA-9f7m-4f22-54r8CGA-9q43-wpvg-8gj3CGA-c34v-wrpp-mq63CGA-c626-9rrg-hggmCGA-c755-76mc-55hfCGA-c984-5fvh-9g4wCGA-cfpg-xmr8-cfv8CGA-cgr9-33g2-7w48CGA-chrm-fxg2-7cvvCGA-cp5f-4fg6-f5wfCGA-cp8r-cjhp-mf62CGA-cpp2-2r79-9pmxCGA-crrr-vhm6-9gw5CGA-crxm-78j9-97p5CGA-f83v-j2g3-rrp9CGA-f885-m7hc-3hm2CGA-f8mj-wff5-v6c7CGA-fh6x-35g8-j8gwCGA-fx47-xjm6-c8gwCGA-g8x7-7rgj-c3wxCGA-g9g9-rpmx-pg56CGA-gg8c-cf87-wjq8CGA-gh2j-4rcq-5h9mCGA-ghr2-v4j6-5jhgCGA-gw4p-3852-v4wrCGA-gxmp-g4fp-54pfCGA-h5rq-xpwh-pxw6CGA-h69g-66cg-4p75CGA-h7f9-jjp2-p56pCGA-h857-xj87-36j2CGA-hfjx-mwh3-6433CGA-hj4q-p8wv-ffpwCGA-hp84-w357-3xqxCGA-j36j-xmh9-hrmqCGA-j594-gj5x-ph8fCGA-j5gg-x757-8v7xCGA-j8qf-3vmh-8qgrCGA-j9r2-73c7-j3jjCGA-jcgg-8222-6x2xCGA-jqj2-cxr7-jr46CGA-jv7f-7gf8-874vCGA-jwgp-4f45-8p79CGA-m393-x8jw-jw4vCGA-m3g9-cv68-mx2qCGA-m4cr-hh56-q22qCGA-m4g5-fq4p-668gCGA-m5pg-9chf-g4c6CGA-m9vp-737f-h7p8CGA-mjw4-v22j-7vvcCGA-mppr-h46h-7pj2CGA-mq2j-qq2g-rqx9CGA-mv26-qp3w-6569CGA-mw2m-jq8r-fc4pCGA-p29m-qxwg-vcmrCGA-p2px-jv28-v74qCGA-p8ff-cxrw-x3pqCGA-p8jm-2p4v-pc3gCGA-p8v2-2hwx-h6rhCGA-p9vv-j38v-qr9hCGA-p9wf-739p-93mcCGA-pj6q-6jjj-9r3vCGA-ppmv-cmg2-w7p7CGA-pqhr-3qhc-pg67CGA-pv78-j3v5-wx35CGA-pwwv-wrhp-x4h3CGA-pxvw-29c7-m4w6CGA-q2qx-4257-wm9wCGA-q45c-fx2h-frqwCGA-q466-q7v9-82h3CGA-q5w9-24jc-vrrqCGA-q6f4-qmg6-pmg7CGA-q7c7-p9mc-9pmmCGA-q934-9h7x-5m4fCGA-qf36-g8pw-mh58CGA-qhcg-2pq8-wj6rCGA-qhq8-q4fc-jf3qCGA-qmqw-h3w7-4c5vCGA-qpgc-r4qf-fxfrCGA-qph6-5rfh-m4cxCGA-qw3f-9w89-27wxCGA-r26c-c34v-chv9CGA-r35x-qj9x-qh3fCGA-r5g8-mmgw-rhxhCGA-r68g-xhvm-q38fCGA-r7fp-qj3g-69rwCGA-r847-hf6j-xx95CGA-r8g2-fjvr-23jpCGA-r9jj-cgr3-v6rmCGA-rc54-mfqp-9x3qCGA-rcxj-84fx-x73gCGA-rf39-x457-473xCGA-rmpw-63rp-6pp2CGA-rp2x-cf76-qqm8CGA-rvwr-52wx-cvw4CGA-rx2w-34ch-5w8hCGA-v275-2m8q-269fCGA-v4qv-6q9h-6w99CGA-v5p7-6gwc-vqp3CGA-v75q-2262-r79hCGA-v78g-j3vh-xp78CGA-v79j-pq75-wrj5CGA-v7j3-x2cr-x5phCGA-v7jw-r22f-566wCGA-vjfv-vf49-jf8rCGA-vmrp-88rf-944pCGA-vpj6-4v68-c975CGA-vr9x-q86m-v92pCGA-vv6h-23h4-x9m8CGA-w2c2-xjj3-xg33CGA-w2hj-c68m-rx7wCGA-w46m-5x28-fj8pCGA-w4cx-vwp9-w8xmCGA-w62f-39qf-xfcpCGA-w773-wcw2-c4q7CGA-w7rq-p7x7-mv4rCGA-wcm2-w8hf-jr5mCGA-wg2m-9977-pgcvCGA-wg8x-5p2v-rqcwCGA-wj22-6w43-57cjCGA-wjj6-wvc8-qfm9CGA-wvhm-59g6-98gmCGA-wvqc-r272-4gh5CGA-x399-7w4m-qmmvCGA-x457-354p-667jCGA-x557-mx4p-m66jCGA-x5x6-293r-8jrmCGA-x69j-r28x-crxpCGA-x72w-qcq8-mghfCGA-x9qx-4432-jfwpCGA-xccx-p4mw-6hqfCGA-xcv3-3r3w-7xx8CGA-xfg8-r8mc-xh5xCGA-xfjx-576r-x86wCGA-xfvp-5h4r-mcpmCGA-xhmr-3grj-589xCGA-xjmr-q28w-q6vhCGA-xm95-g67x-7wv9CGA-xmpp-33v8-xc5gCGA-xq3j-ph7p-88jqCGA-xr34-j696-g2c8CGA-xxm6-fm87-39w5CGA-mr5f-m23f-4mjfCGA-wcvr-wrw2-gp5g
Analyzed
Published: 11 Jun 2026, 15:42
Last modified:13 Jun 2026, 02:20

Vulnerability Summary

Overall Risk (default)
medium
43/100
CVSS Score
8.2 HIGH
v3.1 (nvd)
EPSS Score
0.43% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

11 Jun 2026, 15:42
Published
Vulnerability first disclosed
13 Jun 2026, 02:20
Last Modified
Vulnerability information updated

Description

tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal vulnerability that allows escaping the intended temporary directory when untrusted data flows into the prefix, postfix, or dir options. By embedding traversal sequences (e.g., ../) or path separators in these parameters, attackers can cause files to be created outside the configured temporary base directory at attacker-controlled locations with the privileges of the running process. This vulnerability affects applications that pass user-controlled data to tmp's file/directory creation functions without proper input sanitization. This vulnerability is fixed in 0.2.6.

CVSS Metrics

  • v4.0HIGHScore: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
  • v4.0HIGHScore: 7.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.1HIGHScore: 8.2CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L

EPSS Trends

Current EPSS score: 0.43% Percentile: 37%

Techniques & Countermeasures

  • CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Affected Systems

  • chainguardarangodb-3.11

    < 3.11.14.4-r3

  • chainguardarangodb-3.12

    < 3.12.9.4-r24

  • chainguardauthentik-2025.12

    all

  • chainguardauthentik-2026.2

    < 2026.2.4-r11

  • chainguardauthentik-2026.5

    < 2026.5.3-r5

  • chainguardauthentik-fips-2025.12

    all

  • chainguardauthentik-fips-2026.2

    < 2026.2.4-r10

  • chainguardauthentik-fips-2026.5

    < 2026.5.3-r4

  • chainguarddrupal-11.3

    < 11.3.13-r3

  • chainguardgitlab-rails-ce-18.1

    all

  • chainguardgitlab-rails-ce-18.10

    all

  • chainguardgitlab-rails-ce-18.11

    all

  • chainguardgitlab-rails-ce-18.5

    all

  • chainguardgitlab-rails-ce-18.6

    all

  • chainguardgitlab-rails-ce-18.7

    all

  • chainguardgitlab-rails-ce-18.8

    all

  • chainguardgitlab-rails-ce-18.9

    all

  • chainguardgitlab-rails-ce-19.0

    all

  • chainguardgitlab-rails-ce-19.1

    all | < 19.1.7-r6

  • chainguardgitlab-rails-ce-19.2

    all | < 19.2.5-r2

  • chainguardgitlab-rails-ce-19.3

    < 19.3.1-r6

  • chainguardgitlab-rails-ce-fips-18.1

    all

  • chainguardgitlab-rails-ce-fips-18.10

    all

  • chainguardgitlab-rails-ce-fips-18.11

    all

  • chainguardgitlab-rails-ce-fips-18.5

    all

  • chainguardgitlab-rails-ce-fips-18.6

    all

  • chainguardgitlab-rails-ce-fips-18.7

    all

  • chainguardgitlab-rails-ce-fips-18.8

    all

  • chainguardgitlab-rails-ce-fips-18.9

    all

  • chainguardgitlab-rails-ce-fips-19.0

    all

  • chainguardgitlab-rails-ce-fips-19.1

    all | < 19.1.7-r7

  • chainguardgitlab-rails-ce-fips-19.2

    all | < 19.2.5-r2

  • chainguardgitlab-rails-ce-fips-19.3

    < 19.3.1-r3

  • chainguardhomepage

    < 1.13.2-r1

  • chainguardjupyter-base-notebook

    all

  • chainguardkatib-earlystopping

    < 0.19.0-r31

  • chainguardkatib-suggestion-goptuna-compat

    < 0.19.0-r40

  • chainguardkatib-suggestion-hyperband

    < 0.19.0-r31

  • chainguardkatib-suggestion-hyperopt

    < 0.19.0-r31 | < 0.19.0-r40

  • chainguardkatib-suggestion-nas-darts

    < 0.19.0-r31

  • chainguardkatib-suggestion-nas-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-optuna-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-pbt-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-skopt-enas

    < 0.19.0-r31

  • chainguardkatib-tfevent-metricscollector

    < 0.19.0-r31

  • chainguardkibana-8.17

    < 8.17.10-r22

  • chainguardkibana-8.17-bitnami

    < 8.17.10-r22

  • chainguardkibana-8.17-iamguarded

    < 8.17.10-r22

  • chainguardlangfuse-2-worker

    < 2.95.12-r24

  • chainguardlangfuse-fips-2-worker

    < 2.95.12-r26

Showing first 50 affected entries in server-rendered view.

References (6)