MEDIUM6.8
PYSEC-2026-1845
pytest has vulnerable tmpdir handling
Quick fix
PYSEC-2026-1845 — pytest: upgrade to the fixed version with the command below.
pip install --upgrade 'pytest>=9.0.3'Details
pytest through 9.0.2 on UNIX relies on directories with the `/tmp/pytest-of-{user}` name pattern, which allows local users to cause a denial of service or possibly gain privileges.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-71176[ADVISORY]
- https://github.com/pytest-dev/pytest/issues/13669[WEB]
- https://github.com/pytest-dev/pytest/pull/14343[WEB]
- https://github.com/pytest-dev/pytest/commit/95d8423bd24992deea5b9df32555fa1741679e2c[WEB]
- https://github.com/pytest-dev/pytes[PACKAGE]
- https://github.com/pytest-dev/pytest/releases/tag/9.0.3[WEB]
- https://www.openwall.com/lists/oss-security/2026/01/21/5[WEB]
- https://pypi.org/project/pytest[PACKAGE]
- https://github.com/advisories/GHSA-6w46-j5rx-g56g[ADVISORY]