Junglewise Threat Intelligence

CVE-2025-71176: pytest insecure temporary directory handling on UNIX

CVE-2025-71176 · Severity: medium · CVSS 6.8 · Published 2026-01-22

Vendors: PyPI.

Executive brief

pytest is a popular Python testing framework used by developers to write and run software tests. In versions prior to 9.0.3 on UNIX-like systems, the tool creates temporary directories using a predictable naming pattern. A malicious local user could exploit this behavior to disrupt testing operations or potentially gain unauthorized access to files or privileges on the shared system.

Technical details

pytest versions prior to 9.0.3 on UNIX-like operating systems are vulnerable to insecure temporary directory management (CWE-379). The framework uses a predictable naming convention for temporary directories located in /tmp, specifically following the pattern '/tmp/pytest-of-{user}'. Because these directories may be created with insecure permissions or in a way that allows for symlink attacks or race conditions, a local attacker can pre-create these paths to cause a denial of service or attempt to escalate privileges. The issue is resolved in version 9.0.3 by improving how temporary paths are handled.

Affected products

  • pytest-dev pytest < 9.0.3

Timeline

  • 2026-01-22: disclosed
  • 2026-01-22: advisory
  • 2026-04-13: patched: Advisory updated to reflect patch availability in 9.0.3

References