bash-git-prompt 2.6.1 through 2.7.1 insecurely uses the /tmp/git-index-private$$ file, which has a predictable name.
{ "versions": [ { "introduced": "2.6.1" }, { "last_affected": "2.7.1" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-61659.json"