Impact
At startup, Yazi creates a runtime directory under $XDG_RUNTIME_DIR using DirBuilder::new().mode(0o700).create(path), where the Unix socket file for IPC resides. However, when $XDG_RUNTIME_DIR is not defined, it falls back to /tmp/yazi+{uid}/.
DirBuilder.mode(0o700) only applies permissions to newly created directories. Unlike $XDG_RUNTIME_DIR, /tmp is a globally shared directory, which means an attacker can create /tmp/yazi+{uid}/ in advance before Yazi starts, bypassing the permission setting on it.
As a result, Yazi may start with an attacker-controlled runtime directory, and the attacker can craft the directory and the socket file under it to remotely exploit Yazi.
Patches
Fixed in #4008 (released with v26.8.15).
Yazi now performs an additional unconditional fchmod after DirBuilder.create() to enforce the directory mode as 0o700 (owned by the current user), and checks that the directory's uid matches the current user's uid to reject directories owned by other users.
Impact
At startup, Yazi creates a runtime directory under
$XDG_RUNTIME_DIRusingDirBuilder::new().mode(0o700).create(path), where the Unix socket file for IPC resides. However, when$XDG_RUNTIME_DIRis not defined, it falls back to/tmp/yazi+{uid}/.DirBuilder.mode(0o700)only applies permissions to newly created directories. Unlike$XDG_RUNTIME_DIR,/tmpis a globally shared directory, which means an attacker can create/tmp/yazi+{uid}/in advance before Yazi starts, bypassing the permission setting on it.As a result, Yazi may start with an attacker-controlled runtime directory, and the attacker can craft the directory and the socket file under it to remotely exploit Yazi.
Patches
Fixed in #4008 (released with v26.8.15).
Yazi now performs an additional unconditional
fchmodafterDirBuilder.create()to enforce the directory mode as0o700(owned by the current user), and checks that the directory'suidmatches the current user'suidto reject directories owned by other users.