CVE Explorer
CVE-2026-25645
Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulner
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"requests","vendor":"psf","versions":[{"status":"affected","version":"< 2.33.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:0e84b35968a287db86871687c948e424d3d92fc4c498893f432330af6b47aa8a · sha256:7c6439d488fa906c… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":4.4,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:0e84b35968a287db86871687c948e424d3d92fc4c498893f432330af6b47aa8a · sha256:7c6439d488fa906c… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-377","description":"CWE-377: Insecure Temporary File","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:0e84b35968a287db86871687c948e424d3d92fc4c498893f432330af6b47aa8a · sha256:7c6439d488fa906c… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/psf/requests/commit/66d21cb07bd6255b1280291c4fafb71803cdb3b7","tags":["x_refsource_MISC"],"url":"https://github.com/psf/requests/commit/66d21cb07bd6255b1280291c4fafb71803cdb3b7"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:0e84b35968a287db86871687c948e424d3d92fc4c498893f432330af6b47aa8a · sha256:7c6439d488fa906c… · /containers/cna/references/1
{"name":"https://github.com/psf/requests/releases/tag/v2.33.0","tags":["x_refsource_MISC"],"url":"https://github.com/psf/requests/releases/tag/v2.33.0"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:0e84b35968a287db86871687c948e424d3d92fc4c498893f432330af6b47aa8a · sha256:7c6439d488fa906c… · /containers/cna/references/2
{"name":"https://github.com/psf/requests/security/advisories/GHSA-gc5v-m9x4-r6x2","tags":["x_refsource_CONFIRM"],"url":"https://github.com/psf/requests/security/advisories/GHSA-gc5v-m9x4-r6x2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:0e84b35968a287db86871687c948e424d3d92fc4c498893f432330af6b47aa8a · sha256:7c6439d488fa906c… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.