CVE-2023-29465: Sagemath Flintqs
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
SageMath FlintQS 1.0 relies on pathnames under TMPDIR (typically world-writable), which (for example) allows a local user to overwrite files with the privileges of a different user (who is running FlintQS).
Affected products
- Sagemath Flintqs: version 1.0 only
Published 2023-04-06. Last modified 2026-06-17.