Skip to main content

Vendor/product archive

raszi / tmp CVEs

Beta · best-effort

3 CVEs tagged to raszi / tmp0 Critical, 2 High, 0 Medium, 1 Low, 0 Unrated.

CVE-2026-49982

Published Jun 11, 2026

tmp is a temporary file and directory creator for node.js. In version 0.2.6, the _assertPath guard added to tmp rejects only string values that contain the substring ... It is byp…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44705

Published Jun 11, 2026

tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal vulnerability that allows escaping the intended temporary…

CVSS 7.7 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-54798

Published Aug 7, 2025

tmp is a temporary file and directory creator for node.js. In versions 0.2.3 and below, tmp is vulnerable to an arbitrary temporary file / directory write via symbolic link dir pa…

CVSS 2.5 · Low
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1