Attr Attrproject Attr

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Attrproject Attr.

By the Year

In 2026 there have been 1 vulnerability in Attrproject Attr with an average score of 6.3 out of ten.

Year Vulnerabilities Average Score
2026 1 6.30

It may take a day or so for new Attr vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Attrproject Attr Security Vulnerabilities

Local Priv Escalation via Symlink Traversal in attr <2.6.0 Getfattr/Setfattr
CVE-2026-54371 6.3 - Medium - June 29, 2026

attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.

insecure temporary file

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Attrproject Attr or by Attrproject? Click the Watch button to subscribe.

Attrproject
Vendor

subscribe