CVE-2025-27148
Last modified
CVE-2025-27148 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. On Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delete files within it. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. On Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delete files within it. This library initialization could be vulnerable to a local privilege escalation from an attacker quickly deleting and recreating files in the system temporary directory. Gradle builds that rely on versions of net.rubygrapefruit:native-platform prior to 0.22-milestone-28 could be vulnerable to a local privilege escalation from an attacker quickly deleting and recreating files in the system temporary directory. In net.rubygrapefruit:native-platform prior to version 0.22-milestone-28, if the `Native.get(Class<>)` method was called, without calling `Native.init(File)` first, with a non-`null` argument used as working file path, then the library would initialize itself using the system temporary directory and NativeLibraryLocator.java lines 68 through 78. Version 0.22-milestone-28 has been released with changes that fix the problem. Initialization is now mandatory and no longer uses the system temporary directory, unless such a path is passed for initialization. The only workaround for affected versions is to make sure to do a proper initialization, using a location that is safe. Gradle 8.12, only that exact version, had codepaths where the initialization of the underlying native integration library took a default path, relying on copying the binaries to the system temporary directory. Any execution of Gradle exposed this exploit. Users of Windows or modern versions of macOS are not vulnerable, nor are users of a Unix-like operating system with the "sticky" bit set or `noexec` on their system temporary directory vulnerable. This problem was fixed in Gradle 8.12.1. Gradle 8.13 release also upgrades to a version of the native library that no longer has that bug. Some workarounds are available. On Unix-like operating systems, ensure that the "sticky" bit is set. This only allows the original user (or root) to delete a file. Mounting `/tmp` as `noexec` will prevent Gradle 8.12 from starting. Those who are are unable to change the permissions of the system temporary directory can move the Java temporary directory by setting the System Property java.io.tmpdir. The new path needs to limit permissions to the build user only.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-27148?
How severe is CVE-2025-27148?
How do I fix CVE-2025-27148?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-27142LocalSend is a free, open-source app that allows users to se…8.8
- CVE-2025-27143Better Auth is an authentication and authorization library f…6.1
- CVE-2025-27144Go JOSE provides an implementation of the Javascript Object …6.6
- CVE-2025-27145copyparty, a portable file server, has a DOM-based cross-sit…6.1
- CVE-2025-27146matrix-appservice-irc is a Node.js IRC bridge for Matrix. Th…4.3
- CVE-2025-27147The GLPI Inventory Plugin handles various types of tasks for…8.2
- CVE-2025-27149Zulip server provides an open-source team chat that helps te…2.7
- CVE-2025-2715A vulnerability classified as problematic has been found in …5.1
- CVE-2025-27150Tuleap is an Open Source Suite to improve management of soft…6.5
- CVE-2025-27151Redis is an open source, in-memory database that persists on…9.8
- CVE-2025-27152axios is a promise based HTTP client for the browser and nod…5.3
- CVE-2025-27153Escalade GLPI plugin is a ticket escalation process helper f…6.5
Are you affected by CVE-2025-27148?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
