{"id":"CVE-2026-53759","aliases":["GHSA-r35r-fpx2-jgr4","PYSEC-2026-2596"],"url":"https://o3.security/vulnerability/CVE-2026-53759","summary":"linuxfabrik-lib: Insecure creation of SQLite databases","details":"linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to version 4.2.0, db_sqlite.py created SQLite databases at predictable paths in the shared /tmp directory and followed attacker-created symbolic links at those paths. An attacker who controls a local monitoring account can create a symlink such as /tmp/linuxfabrik-monitoring-plugins-docker-stats.db and then trigger a sudo-authorized plugin, causing the root process to create or modify the symlink target. The primitive can overwrite arbitrary paths, cause denial of service, or manipulate an existing SQLite database through a crafted rollback journal or write-ahead log. The Monitoring Plugins integration also moved plugin caches through lib.db_sqlite.get_db_path() so they use the secured per-user directory. This issue is fixed in version 4.2.0.","published":"2026-08-18T20:54:38.537Z","modified":"2026-08-23T03:42:40.939533763Z","cvss":null,"epss":{"score":0.00184,"percentile":0.08006,"asOf":"2026-09-07"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"linuxfabrik-lib","fixedVersion":"4.2.0"}],"fix":{"url":"https://github.com/Linuxfabrik/lib/commit/1e3ca61d45e37ef118aa0c107b420ef74458697e","label":"Linuxfabrik/lib@1e3ca61"},"references":[{"type":"WEB","url":"https://github.com/Linuxfabrik/lib/blob/main/CHANGELOG.md#v420---2026-06-02"},{"type":"WEB","url":"https://github.com/Linuxfabrik/lib/releases/tag/v4.2.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53759.json"},{"type":"ADVISORY","url":"https://github.com/Linuxfabrik/monitoring-plugins/security/advisories/GHSA-r35r-fpx2-jgr4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53759"},{"type":"FIX","url":"https://github.com/Linuxfabrik/lib/commit/1e3ca61d45e37ef118aa0c107b420ef74458697e"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-23T03:42:40.939533763Z"}}