CVE-2025-71176 Overview
CVE-2025-71176 affects the pytest testing framework through version 9.0.2 on UNIX systems. The vulnerability stems from pytest's reliance on predictable temporary directory names following the /tmp/pytest-of-{user} pattern. Local users can exploit this predictable naming scheme to cause a denial of service or potentially gain elevated privileges. The issue is classified under CWE-379: Creation of Temporary File in Directory with Insecure Permissions.
Critical Impact
Local attackers on shared UNIX systems can pre-create or manipulate the predictable /tmp/pytest-of-{user} directory to disrupt test runs or potentially escalate privileges when the pytest user later interacts with those files.
Affected Products
- pytest versions through 9.0.2
- UNIX-based operating systems using shared /tmp directories
- Continuous integration environments running pytest on multi-user hosts
Discovery Timeline
- 2026-01-22 - CVE-2025-71176 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-71176
Vulnerability Analysis
pytest creates a per-user temporary working directory named /tmp/pytest-of-{user} to store test artifacts, fixtures, and cached data. The directory name is deterministic and derived solely from the current username. On multi-user UNIX hosts, any local user can predict this path and create the directory before the legitimate pytest process runs.
Because the target path is predictable, a malicious local user can pre-create /tmp/pytest-of-victim with attacker-controlled permissions, symbolic links, or contents. When the victim later runs pytest, the framework may write to or read from those attacker-influenced paths.
Root Cause
The root cause is insecure temporary directory handling under [CWE-379]. pytest does not verify ownership or use randomized directory names before reusing /tmp/pytest-of-{user}. Predictable paths in world-writable locations like /tmp violate secure temporary file handling practices established for UNIX shared filesystems.
Attack Vector
Exploitation requires local access to a system where pytest will be executed by another user. The attacker pre-creates the predictable directory and can plant symbolic links pointing to sensitive files. When pytest writes test artifacts, those writes may be redirected through the symlinks, causing file overwrite, denial of service, or in specific configurations, privilege escalation if the pytest user has higher privileges than the attacker.
See the upstream GitHub Issue #13669 and the Openwall OSS Security Update for technical discussion of the flaw.
Detection Methods for CVE-2025-71176
Indicators of Compromise
- Presence of /tmp/pytest-of-{user} directories not owned by the expected user
- Symbolic links inside /tmp/pytest-of-* pointing to sensitive files outside the temporary tree
- Unexpected file modifications in user home directories following pytest execution on shared hosts
Detection Strategies
- Audit /tmp for pre-existing pytest-of-* directories with mismatched ownership before test runs
- Enable filesystem auditing (auditd) on /tmp/pytest-of-* paths to record create, chown, and symlink operations
- Review CI/CD job logs for pytest warnings about existing temporary directories or permission errors
Monitoring Recommendations
- Monitor local user activity on shared build and test hosts for suspicious /tmp directory creation
- Alert on symlink creation inside predictable temporary paths used by developer tooling
- Track pytest version inventory across engineering systems to identify unpatched hosts
How to Mitigate CVE-2025-71176
Immediate Actions Required
- Upgrade pytest to a fixed release once published by the pytest-dev maintainers; monitor GitHub Issue #13669 for release status
- Avoid running pytest as a privileged user on multi-tenant UNIX hosts
- Set the PYTEST_DEBUG_TEMPROOT environment variable to a user-private directory outside /tmp
Patch Information
At the time of publication, tracking is handled through the upstream pytest project. Review the GitHub Issue #13669 and the Openwall OSS Security Update for patch availability and version guidance.
Workarounds
- Configure PYTEST_DEBUG_TEMPROOT to point to a directory inside the user's home with mode 0700
- Enable the Linux kernel fs.protected_symlinks and fs.protected_hardlinks sysctls to reduce symlink attack impact
- Restrict interactive access to build hosts so that only trusted users share the local /tmp namespace
# Configuration example: redirect pytest temp root to a private per-user path
mkdir -p "$HOME/.pytest-tmp"
chmod 0700 "$HOME/.pytest-tmp"
export PYTEST_DEBUG_TEMPROOT="$HOME/.pytest-tmp"
# Harden the kernel against symlink and hardlink attacks in /tmp
sudo sysctl -w fs.protected_symlinks=1
sudo sysctl -w fs.protected_hardlinks=1
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
