Executive brief
pytest is a popular Python testing framework used by developers to write and run software tests. In versions prior to 9.0.3 on UNIX-like systems, the tool creates temporary directories using a predictable naming pattern. A malicious local user could exploit this behavior to disrupt testing operations or potentially gain unauthorized access to files or privileges on the shared system.
Technical details
pytest versions prior to 9.0.3 on UNIX-like operating systems are vulnerable to insecure temporary directory management (CWE-379). The framework uses a predictable naming convention for temporary directories located in /tmp, specifically following the pattern '/tmp/pytest-of-{user}'. Because these directories may be created with insecure permissions or in a way that allows for symlink attacks or race conditions, a local attacker can pre-create these paths to cause a denial of service or attempt to escalate privileges. The issue is resolved in version 9.0.3 by improving how temporary paths are handled.
Affected products
- pytest-dev pytest < 9.0.3
Timeline
- 2026-01-22: disclosed
- 2026-01-22: advisory
- 2026-04-13: patched: Advisory updated to reflect patch availability in 9.0.3