CVE-2026-44705
Vulnerability Summary
Timeline
Description
tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal vulnerability that allows escaping the intended temporary directory when untrusted data flows into the prefix, postfix, or dir options. By embedding traversal sequences (e.g., ../) or path separators in these parameters, attackers can cause files to be created outside the configured temporary base directory at attacker-controlled locations with the privileges of the running process. This vulnerability affects applications that pass user-controlled data to tmp's file/directory creation functions without proper input sanitization. This vulnerability is fixed in 0.2.6.
CVSS Metrics
- v4.0•HIGH•Score: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
- v4.0•HIGH•Score: 7.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- v3.1•HIGH•Score: 8.2CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
EPSS Trends
Current EPSS score: 0.43%• Percentile: 37%
Techniques & Countermeasures
- CWE-22•Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Affected Systems
- chainguard•arangodb-3.11
< 3.11.14.4-r3
- chainguard•arangodb-3.12
< 3.12.9.4-r24
- chainguard•authentik-2025.12
all
- chainguard•authentik-2026.2
< 2026.2.4-r11
- chainguard•authentik-2026.5
< 2026.5.3-r5
- chainguard•authentik-fips-2025.12
all
- chainguard•authentik-fips-2026.2
< 2026.2.4-r10
- chainguard•authentik-fips-2026.5
< 2026.5.3-r4
- chainguard•drupal-11.3
< 11.3.13-r3
- chainguard•gitlab-rails-ce-18.1
all
- chainguard•gitlab-rails-ce-18.10
all
- chainguard•gitlab-rails-ce-18.11
all
- chainguard•gitlab-rails-ce-18.5
all
- chainguard•gitlab-rails-ce-18.6
all
- chainguard•gitlab-rails-ce-18.7
all
- chainguard•gitlab-rails-ce-18.8
all
- chainguard•gitlab-rails-ce-18.9
all
- chainguard•gitlab-rails-ce-19.0
all
- chainguard•gitlab-rails-ce-19.1
all | < 19.1.7-r6
- chainguard•gitlab-rails-ce-19.2
all | < 19.2.5-r2
- chainguard•gitlab-rails-ce-19.3
< 19.3.1-r6
- chainguard•gitlab-rails-ce-fips-18.1
all
- chainguard•gitlab-rails-ce-fips-18.10
all
- chainguard•gitlab-rails-ce-fips-18.11
all
- chainguard•gitlab-rails-ce-fips-18.5
all
- chainguard•gitlab-rails-ce-fips-18.6
all
- chainguard•gitlab-rails-ce-fips-18.7
all
- chainguard•gitlab-rails-ce-fips-18.8
all
- chainguard•gitlab-rails-ce-fips-18.9
all
- chainguard•gitlab-rails-ce-fips-19.0
all
- chainguard•gitlab-rails-ce-fips-19.1
all | < 19.1.7-r7
- chainguard•gitlab-rails-ce-fips-19.2
all | < 19.2.5-r2
- chainguard•gitlab-rails-ce-fips-19.3
< 19.3.1-r3
- chainguard•homepage
< 1.13.2-r1
- chainguard•jupyter-base-notebook
all
- chainguard•katib-earlystopping
< 0.19.0-r31
- chainguard•katib-suggestion-goptuna-compat
< 0.19.0-r40
- chainguard•katib-suggestion-hyperband
< 0.19.0-r31
- chainguard•katib-suggestion-hyperopt
< 0.19.0-r31 | < 0.19.0-r40
- chainguard•katib-suggestion-nas-darts
< 0.19.0-r31
- chainguard•katib-suggestion-nas-enas
< 0.19.0-r31
- chainguard•katib-suggestion-optuna-enas
< 0.19.0-r31
- chainguard•katib-suggestion-pbt-enas
< 0.19.0-r31
- chainguard•katib-suggestion-skopt-enas
< 0.19.0-r31
- chainguard•katib-tfevent-metricscollector
< 0.19.0-r31
- chainguard•kibana-8.17
< 8.17.10-r22
- chainguard•kibana-8.17-bitnami
< 8.17.10-r22
- chainguard•kibana-8.17-iamguarded
< 8.17.10-r22
- chainguard•langfuse-2-worker
< 2.95.12-r24
- chainguard•langfuse-fips-2-worker
< 2.95.12-r26
Showing first 50 affected entries in server-rendered view.
References (6)
- https://github.com/raszi/node-tmp/security/advisories/GHSA-ph9p-34f9-6g65
- https://github.com/raszi/node-tmp/commit/efa4a06f24374797ae32ab2b6ae39b7a611ae429
- https://github.com/raszi/node-tmp
- https://nvd.nist.gov/vuln/detail/CVE-2026-44705
- https://security-tracker.debian.org/tracker/CVE-2026-44705
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44705.json