CVE Feed

    Dashboard / CVE / CVE-2026-44705

    CVE-2026-44705

    tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal vulnerability that allows escaping the intended temporary directory when untrusted data flows into the prefix, postfix, or dir options. By embedding traversal sequences (e.g., ../) or path separators in these parameters, attackers can cause files to be created outside the configured temporary base directory at attacker-controlled locations with the privileges of the running process. This vulnerability affects applications that pass user-controlled data to tmp's file/directory creation functions without proper input sanitization. This vulnerability is fixed in 0.2.6.

    Published:Jun 11, 2026
    Last Modified:Jun 15, 2026
    EPS:Jun 11, 2026
    EPSS Score:0.00496
    CVSS Score:8.2

    Affected Products

    Vendor
    Raszi
    Product
    Node-tmp
    Vendor
    Raszi
    Product
    Tmp

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High