CVE-2026-75038CWE-61

CVE-2026-75038

Medium · published August 25, 2026

CVSS v3.1
6.1
EPSS
0%
Percentile
2.2
In the wild
Unconfirmed
What it is

UNIX symbolic link (symlink) following vulnerability in ilya-zlobintsev/LACT allows for local denial-of-service. This issue affects LACT: through 0.10.0.

The record
Technical detail
CVSS v3.1
6.1 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
CVSS v4.0
6.9 · CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
EPSS
0.00122 · 2.2th percentile
Weakness
CWE-61 · UNIX Symbolic Link (Symlink) Following
Published
2026-08-25T14:18Z
References (2)
EPSS history
Timeline
  • 27 AUG 06:45Z
    EPSS moved — → 0%
    epss
  • 25 AUG 10:00Z
    Predictable temporary file in /tmp allows symlink attack in LACT
    cvelistv5