Description
Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to a predictable temporary path and followed symlinks, creating a time-of-check to time-of-use race that allowed a local unprivileged attacker on the same machine to pre-plant a symlink and cause Flameshot to write PNG data through it, overwriting any file the victim user could write. This issue is fixed in version 14.0.0.
Severity (CVSS)
| Base score | 5.1 |
|---|---|
| Severity | Medium |
| Version | CVSS 4.0 |
| Vector | CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N |
| Provided by | CNA |
Weaknesses
- CWE-362 — CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
- CWE-377 — CWE-377: Insecure Temporary File
Affected products
| Vendor | Product | Versions |
|---|---|---|
| flameshot-org | flameshot | < 14.0.0 |
References
- https://github.com/flameshot-org/flameshot/security/advisories/GHSA-fqqf-4rj8-c392 (x_refsource_CONFIRM)
- https://github.com/flameshot-org/flameshot/pull/4716 (x_refsource_MISC)
- https://github.com/flameshot-org/flameshot/commit/936716b8d8b7052be461c3d5e2f88492b6eb3b96 (x_refsource_MISC)
- https://github.com/flameshot-org/flameshot/releases/tag/v14.0.0 (x_refsource_MISC)
Generated from the official CVE List on 16 Jul 2026 07:01 UTC.