CVE-2025-9810 is a Time-of-Check to Time-of-Use (TOCTOU) vulnerability in the linenoiseHistorySave function of the antirez linenoise library. This flaw allows local attackers to overwrite arbitrary files and change permissions via a symlink race condition. Rated Medium (CVSS 5.8), this vulnerability requires high attack complexity and local access, potentially leading to high integrity impact, along with low confidentiality and availability impacts. There is currently no evidence of active exploitation, nor are public exploits available in common databases like Metasploit or ExploitDB. Community discussion and media coverage are also absent, indicating low current attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:antirez:linenoise:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.