


Perceptive Security
SOC/SIEM Consultancy

CodexBar prior to 0.32.0 contains an insecure temporary file handling vulnerability that allows local attackers to access sensitive credentials or tamper with b…
Published:
31 May 2026 at 22:00:00
Alert date:
1 June 2026 at 22:04:03
Source:
nvd.nist.gov
Enterprise Applications, Supply Chain & Dependencies
CodexBar versions prior to 0.32.0 contain an insecure temporary file handling vulnerability in the release notarization workflow. Local attackers can exploit predictable file paths to access sensitive credentials including App Store Connect API keys or tamper with build artifacts. Attackers with host access can read API keys from fixed paths, pre-create files or symbolic links at predictable locations to redirect writes to attacker-controlled destinations, or modify notarization archives before submission. The vulnerability has been addressed in version 0.32.0.
Technical details
Mitigation steps:
Affected products:
CodexBar
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-49135
https://github.com/steipete/CodexBar/commit/e7d932616508cee43ea9bcc63c269b14698de655
https://github.com/steipete/CodexBar/pull/1228
https://github.com/steipete/CodexBar/releases/tag/v0.32.0
https://www.vulncheck.com/advisories/codexbar-insecure-temporary-file-handling-in-notarization-workflow
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
