pleaseedit in pleaser before 0.4.0 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack.
{ "nvd_published_at": "2021-05-27T13:15:00Z", "github_reviewed_at": "2021-06-01T19:34:12Z", "severity": "HIGH", "github_reviewed": true, "cwe_ids": [ "CWE-340", "CWE-59" ] }