CVE-2026-62294

Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to a predictable temporary path and followed symlinks, creating a time-of-check to time-of-use race that allowed a local unprivileged attacker on the same machine to pre-plant a symlink and cause Flameshot to write PNG data through it, overwriting any file the victim user could write. This issue is fixed in version 14.0.0.
CVSS

No CVSS.

Configurations

No configuration.

History

15 Jul 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-15 15:16

Updated : 2026-07-15 20:56


NVD link : CVE-2026-62294

Mitre link : CVE-2026-62294

CVE.ORG link : CVE-2026-62294


JSON object : View

Products Affected

No product.

CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CWE-377

Insecure Temporary File