An insecure temporary file creation vulnerability exists in the AutoExtract component of Robocode version 1.9.3.6. The createTempFile method fails to securely create temporary files, allowing attackers to exploit race conditions and potentially execute arbitrary code or overwrite critical files. This vulnerability can be exploited by manipulating the temporary file creation process, leading to potential unauthorized actions.
History

Wed, 10 Dec 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Robocode Project
Robocode Project robocode
Vendors & Products Robocode Project
Robocode Project robocode

Tue, 09 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 09 Dec 2025 07:45:00 +0000

Type Values Removed Values Added
Description An insecure temporary file creation vulnerability exists in the AutoExtract component of Robocode version 1.9.3.6. The createTempFile method fails to securely create temporary files, allowing attackers to exploit race conditions and potentially execute arbitrary code or overwrite critical files. This vulnerability can be exploited by manipulating the temporary file creation process, leading to potential unauthorized actions.
Title Insecure Temporary File Creation in Robocode's AutoExtract Component
Weaknesses CWE-377
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/AU:Y/R:U/V:D/RE:M/U:Red'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GovTech CSG

Published: 2025-12-09T07:29:52.225Z

Updated: 2025-12-09T16:02:14.880Z

Reserved: 2025-12-09T07:25:41.010Z

Link: CVE-2025-14307

cve-icon Vulnrichment

Updated: 2025-12-09T14:23:15.291Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-09T16:17:38.640

Modified: 2025-12-09T18:37:13.640

Link: CVE-2025-14307

cve-icon Redhat

No data.