CVE-2025-9810: Antirez Linenoise
Medium severity, CVSS 5.8. EPSS: 0.1% chance of exploitation in the next 30 days.
TOCTOU in linenoiseHistorySave in linenoise allows local attackers to overwrite arbitrary files and change permissions via a symlink race between fopen("w") on the history path and subsequent chmod() on the same path.
Affected products
- Antirez Linenoise: affected versions not specified
Published 2025-09-01. Last modified 2026-06-17.