pleaseedit in pleaser before 0.4.0 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack.
{
"nvd_published_at": "2021-05-27T13:15:00Z",
"severity": "HIGH",
"cwe_ids": [
"CWE-340",
"CWE-59"
],
"github_reviewed_at": "2021-06-01T19:34:12Z",
"github_reviewed": true
}