Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Steipete
Steipete codexbar |
|
| Vendors & Products |
Steipete
Steipete codexbar |
Tue, 02 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CodexBar prior to 0.32.0 contains a privilege escalation vulnerability in the CLI installer that allows local attackers to execute arbitrary commands as root by exploiting a race condition in temporary file handling. The installer creates a temporary file with mktemp, writes a privileged shell payload into it, and executes it with administrator privileges via bash, allowing a same-user local process to rewrite the installer body before the administrator prompt is approved, causing attacker-controlled commands to run as root. | |
| Title | CodexBar < 0.32.0 Privilege Escalation via CLI Installer Temp File | |
| Weaknesses | CWE-377 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-02T12:39:10.759Z
Reserved: 2026-05-27T17:40:12.738Z
Link: CVE-2026-49134
Updated: 2026-06-02T12:38:39.851Z
Status : Deferred
Published: 2026-06-01T21:16:46.353
Modified: 2026-06-02T14:43:49.920
Link: CVE-2026-49134
No data.
OpenCVE Enrichment
Updated: 2026-06-02T20:52:49Z