From 18dceb3c3227280351e72ee3c24e1bed83c6e623 Mon Sep 17 00:00:00 2001 From: maziggy Date: Sun, 12 Apr 2026 15:10:40 +0200 Subject: [PATCH] . --- CHANGELOG.md | 3 +++ backend/app/api/routes/settings.py | 5 ++++- 2 files changed, 7 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index f8588b42c..d0303a94a 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,9 @@ All notable changes to Bambuddy will be documented in this file. ## [0.2.3b4] - Unreleased +### Fixed +- **Insecure Temp File Creation in Backup Export** — The manual backup download endpoint used `tempfile.mktemp()`, which is vulnerable to a symlink race condition (CWE-377). Replaced with `tempfile.mkstemp()` which atomically creates the file, eliminating the TOCTOU window. + ## [0.2.3b3] - 2026-04-12 diff --git a/backend/app/api/routes/settings.py b/backend/app/api/routes/settings.py index 571609e5a..39442c15e 100644 --- a/backend/app/api/routes/settings.py +++ b/backend/app/api/routes/settings.py @@ -1,5 +1,6 @@ import io import logging +import os import zipfile from datetime import datetime from pathlib import Path @@ -457,7 +458,9 @@ async def create_backup_zip(output_path: Path | None = None) -> tuple[Path, str] if output_path is not None: zip_file = output_path / filename else: - zip_file = Path(tempfile.mktemp(suffix=".zip")) # noqa: S306 + fd, tmp = tempfile.mkstemp(suffix=".zip") + os.close(fd) + zip_file = Path(tmp) with zipfile.ZipFile(zip_file, "w", zipfile.ZIP_DEFLATED) as zf: for file_path in temp_path.rglob("*"):