Tmate is a terminal-sharing and remote-access tool centered on its SSH server component, serving developers and operations teams who need to collaborate on shared terminal sessions. Its vulnerability profile reflects the concurrent-access nature of shared terminal infrastructure, with observed weaknesses clustering around race conditions and improper permission assignment on critical resources. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tmate over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-44513HIGH Insecure creation of temporary directories in tmate-ssh-server 2.3.0 allows a local attacker to compromise the integrity of session handling. | Dec 7, 2021 | 7.0 | 24 | NO | NO |
CVE-2021-44512HIGH World-writable permissions on the /tmp/tmate/sessions directory in tmate-ssh-server 2.3.0 allow a local attacker to compromise the integrity of session handling, or obtain the read | Dec 7, 2021 | 7.0 | 23 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tmate.
Media articles that mention a CVE ID that affects a product developed by Tmate — matched by CVE ID, not by vendor name.