CVE-2026-49135 Details
Description
CodexBar prior to 0.32.0 contains an insecure temporary file handling vulnerability that allows local attackers to access sensitive credentials or tamper with build artifacts by exploiting predictable file paths in the release notarization workflow. Attackers with access to the same host can read the App Store Connect API key written to a fixed path, pre-create files or symbolic links at predictable locations to redirect writes to attacker-controlled destinations, or tamper with notarization archives before submission.
A vulnerability exists in CodexBar versions prior to 0.32.0, related to insecure handling of temporary files during the release notarization process. This flaw allows local attackers to access sensitive credentials or manipulate build artifacts by taking advantage of predictable file paths. Attackers on the same host can read the App Store Connect API key, which is written to a fixed location, pre-create files or symbolic links to redirect writes to locations they control, or tamper with notarization archives before they are submitted.
Users can upgrade to CodexBar version 0.32.0 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 1, 2026CISA-ADP
Assessed Jun 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/steipete/CodexBar/pull/1228 | CISA-ADP | Issue TrackingVendor |
| https://github.com/steipete/CodexBar/commit/e7d932616508cee43ea9bcc63c269b14698de655 | [email protected] | Source CodeVendor |
| https://github.com/steipete/CodexBar/pull/1228 | [email protected] | Issue TrackingVendor |
| https://github.com/steipete/CodexBar/releases/tag/v0.32.0 | [email protected] | Release NotesVendor |
| https://www.vulncheck.com/advisories/codexbar-insecure-temporary-file-handling-in-notarization-workflow | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-377 | Insecure Temporary File | [email protected] |
| CWE-59 | Improper Link Resolution Before File Access ('Link Following') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| CodexBar | < 0.32.0 (semver) |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 2, 2026 | CVE Modified | CISA-ADP |
| Jun 1, 2026 | New CVE Received | [email protected] |
Volerion