CVE-2025-70341

Insecure permissions in App-Auto-Patch v3.4.2 create a race condition which allows attackers to write arbitrary files.
Configurations

Configuration 1 (hide)

cpe:2.3:a:app-auto-patch:app-auto-patch:*:*:*:*:*:*:*:*

History

05 Mar 2026, 18:19

Type Values Removed Values Added
First Time App-auto-patch app-auto-patch
App-auto-patch
CPE cpe:2.3:a:app-auto-patch:app-auto-patch:*:*:*:*:*:*:*:*
References () https://github.com/App-Auto-Patch/App-Auto-Patch/blob/main/App-Auto-Patch-via-Dialog.zsh - () https://github.com/App-Auto-Patch/App-Auto-Patch/blob/main/App-Auto-Patch-via-Dialog.zsh - Product
References () https://github.com/App-Auto-Patch/App-Auto-Patch/issues/203 - () https://github.com/App-Auto-Patch/App-Auto-Patch/issues/203 - Issue Tracking
References () https://github.com/App-Auto-Patch/App-Auto-Patch/pull/202 - () https://github.com/App-Auto-Patch/App-Auto-Patch/pull/202 - Patch
References () https://github.com/malvector/CVE-2025-70341 - () https://github.com/malvector/CVE-2025-70341 - Exploit, Third Party Advisory

04 Mar 2026, 16:16

Type Values Removed Values Added
CWE CWE-94
CWE-732
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

04 Mar 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-04 15:16

Updated : 2026-03-05 18:19


NVD link : CVE-2025-70341

Mitre link : CVE-2025-70341

CVE.ORG link : CVE-2025-70341


JSON object : View

Products Affected

app-auto-patch

  • app-auto-patch
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-732

Incorrect Permission Assignment for Critical Resource