Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to a predictable temporary path and followed symlinks, creating a time-of-check to time-of-use race that allowed a local unprivileged attacker on the same machine to pre-plant a symlink and cause Flameshot to write PNG data through it, overwriting any file the victim user could write. This issue is fixed in version 14.0.0.
History

Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Flameshot-org
Flameshot-org flameshot
Vendors & Products Flameshot-org
Flameshot-org flameshot

Wed, 15 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to a predictable temporary path and followed symlinks, creating a time-of-check to time-of-use race that allowed a local unprivileged attacker on the same machine to pre-plant a symlink and cause Flameshot to write PNG data through it, overwriting any file the victim user could write. This issue is fixed in version 14.0.0.
Title Flameshot: OCTOU symlink attack via predictable /tmp path in Flameshot "Open With"
Weaknesses CWE-362
CWE-377
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2026-07-15T14:20:43.746Z

Updated: 2026-07-15T18:00:42.038Z

Reserved: 2026-07-13T18:37:08.488Z

Link: CVE-2026-62294

cve-icon Vulnrichment

Updated: 2026-07-15T18:00:35.476Z

cve-icon NVD

Status : Deferred

Published: 2026-07-15T15:16:49.010

Modified: 2026-07-15T20:56:21.653

Link: CVE-2026-62294

cve-icon Redhat

No data.