The Lab · 2026-03-31 15:27:29 · GitHub Issues
A critical vulnerability in GitHub's handling of temporary directories, tracked as CVE-2025-71176, has been patched after a previous security fix was found to be insufficient. The flaw stemmed from the system following symbolic links, which could allow an attacker to manipulate the temporary directory path and potentia...
The Lab · 2026-04-15 15:22:55 · GitHub Issues
A newly disclosed vulnerability in the widely used Python testing framework, pytest, exposes a critical path for local privilege escalation and denial-of-service attacks on UNIX systems. The flaw, tracked as CVE-2025-71176, stems from the framework's reliance on predictable directory names under `/tmp/pytest-of-{user}`...
The Lab · 2026-04-15 20:23:14 · GitHub Issues
A critical security vulnerability in the widely-used Python testing framework, pytest, exposes UNIX-based systems to local denial-of-service attacks and potential privilege escalation. The flaw, tracked as CVE-2025-71176, is present in all versions up to and including 9.0.2. It stems from the framework's predictable us...
The Lab · 2026-04-15 22:22:53 · GitHub Issues
A critical security vulnerability, CVE-2025-71176, has forced an emergency patch release for the widely-used Python testing framework, pytest. The flaw, present in all versions through 9.0.2 on UNIX systems, involves improper reliance on the `d` system call for temporary directory creation, potentially exposing develop...
The Lab · 2026-04-16 00:22:58 · GitHub Issues
A critical security vulnerability in the popular Python testing framework, pytest, exposes UNIX-based systems to local denial-of-service attacks and potential privilege escalation. The flaw, tracked as CVE-2025-71176, is present in all versions up to and including 9.0.2. It stems from the framework's predictable use of...
The Lab · 2026-04-16 02:22:40 · GitHub Issues
A critical security vulnerability in the widely-used Python testing framework, pytest, exposes UNIX systems to local privilege escalation and denial-of-service attacks. The flaw, tracked as CVE-2025-71176, stems from the framework's predictable use of directories named `/tmp/pytest-of-{user}`. This pattern allows any l...
The Lab · 2026-04-18 17:22:42 · GitHub Issues
A critical security vulnerability in the widely used Python testing framework, pytest, has been disclosed, exposing UNIX-based systems to potential local privilege escalation and denial-of-service attacks. The flaw, tracked as CVE-2025-71176, is present in all versions up to and including 9.0.2. It stems from the frame...
The Lab · 2026-04-26 08:54:08 · GitHub Issues
A critical security vulnerability in the pytest testing framework through version 9.0.2 has been identified, prompting an urgent update to version 9.0.3. The flaw, tracked as CVE-2025-71176, stems from pytest's reliance on predictable temporary directory naming conventions on UNIX systems, specifically directories foll...