CVE-2026-62294

NONE
CVSS v3
CVSS v2
0.10% EPSS (exploit probability)
CWE-362CWE

Description

Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to a predictable temporary path and followed symlinks, creating a time-of-check to time-of-use race that allowed a local unprivileged attacker on the same machine to pre-plant a symlink and cause Flameshot to write PNG data through it, overwriting any file the victim user could write. This issue is fixed in version 14.0.0.

Affected routers (0)

No routers currently mapped to this CVE in our database.

External references