MEDIUM 5.5 PyPI

Arbitrary file write in NumPy

GHSA-cw6w-4rcx-xphc · CVE-2014-1858 · PYSEC-2018-33

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

init.py in f2py in NumPy before 1.8.1 allows local users to write to arbitrary files via a symlink attack on a temporary file.

Ready to move

Start Securing

Free, no credit card | First findings in minutes