CVE-2025-70342: Grahampugh Erase-Install

Medium severity, CVSS 6.6. EPSS: 0.2% chance of exploitation in the next 30 days.

erase-install prior to v40.4 commit 2c31239 writes swiftDialog credential output to a hardcoded path /var/tmp/dialog.json. This allows an unauthenticated attacker to intercept admin credentials entered during reinstall/erase operations via creating a named pipe.

Affected products

  • Grahampugh Erase-Install: before 41.0 (fixed in 41.0)

Published 2026-03-04. Last modified 2026-06-17.