CVE-2026-75038: Predictable temporary file in /tmp allows symlink attack in LACT
Published Aug 25, 2026
·Updated
UNIX symbolic link (symlink) following vulnerability in ilya-zlobintsev/LACT allows for local denial-of-service. This issue affects LACT: through 0.10.0.
Affected Software
1 affected component
ilay-zlobintsev/LACT<0.10.0
Event History
Aug 25, 2026
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A local attacker with low privileges can exploit the issue. The attack requires local access and does not require user interaction.
2
What is the impact of successful exploitation?
Successful exploitation can cause a local denial of service. The provided severity vector also indicates possible integrity impact, but no further impact details are provided.
3
Which versions are affected?
LACT versions through 0.10.0 are affected.