Skip to content

Improper permission setting on fallback runtime directory

Moderate
sxyazi published GHSA-9g7f-j48q-ppp9 Aug 16, 2026

Package

yazi-fm (sxyazi/yazi)

Affected versions

<= 26.5.6

Patched versions

v26.8.15

Description

Impact

At startup, Yazi creates a runtime directory under $XDG_RUNTIME_DIR using DirBuilder::new().mode(0o700).create(path), where the Unix socket file for IPC resides. However, when $XDG_RUNTIME_DIR is not defined, it falls back to /tmp/yazi+{uid}/.

DirBuilder.mode(0o700) only applies permissions to newly created directories. Unlike $XDG_RUNTIME_DIR, /tmp is a globally shared directory, which means an attacker can create /tmp/yazi+{uid}/ in advance before Yazi starts, bypassing the permission setting on it.

As a result, Yazi may start with an attacker-controlled runtime directory, and the attacker can craft the directory and the socket file under it to remotely exploit Yazi.

Patches

Fixed in #4008 (released with v26.8.15).

Yazi now performs an additional unconditional fchmod after DirBuilder.create() to enforce the directory mode as 0o700 (owned by the current user), and checks that the directory's uid matches the current user's uid to reject directories owned by other users.

Severity

Moderate

CVSS overall score

This score calculates overall vulnerability severity from 0 to 10 and is based on the Common Vulnerability Scoring System (CVSS).
/ 10

CVSS v3 base metrics

Attack vector
Local
Attack complexity
High
Privileges required
Low
User interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS v3 base metrics

Attack vector: More severe the more the remote (logically and physically) an attacker can be in order to exploit the vulnerability.
Attack complexity: More severe for the least complex attacks.
Privileges required: More severe if no privileges are required.
User interaction: More severe when no user interaction is required.
Scope: More severe when a scope change occurs, e.g. one vulnerable component impacts resources in components beyond its security scope.
Confidentiality: More severe when loss of data confidentiality is highest, measuring the level of data access available to an unauthorized user.
Integrity: More severe when loss of data integrity is the highest, measuring the consequence of data modification possible by an unauthorized user.
Availability: More severe when the loss of impacted component availability is highest.
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

CVE ID

No known CVE

Weaknesses

Time-of-check Time-of-use (TOCTOU) Race Condition

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. Learn more on MITRE.

Creation of Temporary File With Insecure Permissions

Opening temporary files without appropriate measures or controls can leave the file, its contents and any function that it impacts vulnerable to attack. Learn more on MITRE.

Credits