PT-2026-60196 · Flameshot · Flameshot

CVE-2026-62294

·

Published

2026-07-15

·

Updated

2026-07-15

CVSS v4.0

5.1

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Flameshot versions prior to 14.0.0
Description The Open With feature writes screenshots to a predictable temporary path and follows symlinks. This creates a time-of-check to time-of-use (TOCTOU) race condition—a scenario where a system checks a condition (such as a file's existence) and then uses the result, but the condition changes between the check and the use. A local unprivileged attacker can exploit this by pre-planting a symlink, causing the software to write PNG data through it and overwrite any file the victim user has permissions to write.
Recommendations Update to version 14.0.0.

Exploit

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62294
GHSA-FQQF-4RJ8-C392

Affected Products

Flameshot