{"id":"GHSA-5hgf-628x-mcqf","summary":"uutils coreutils has an Incorrect Permission Assignment for Critical Resource","details":"The nohup utility in uutils coreutils creates its default output file, nohup.out, without specifying explicit restricted permissions. This causes the file to inherit umask-based permissions, typically resulting in a world-readable file (0644). In multi-user environments, this allows any user on the system to read the captured stdout/stderr output of a command, potentially exposing sensitive information. This behavior diverges from GNU coreutils, which creates nohup.out with owner-only (0600) permissions.","aliases":["CVE-2026-35367"],"modified":"2026-09-10T03:50:42.974747384Z","published":"2026-04-22T18:31:45Z","database_specific":{"github_reviewed_at":"2026-04-30T17:50:53Z","nvd_published_at":"2026-04-22T17:16:40Z","cwe_ids":["CWE-732"],"severity":"LOW","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35367"},{"type":"WEB","url":"https://github.com/uutils/coreutils/issues/10021"},{"type":"PACKAGE","url":"https://github.com/uutils/coreutils"}],"affected":[{"package":{"name":"coreutils","ecosystem":"crates.io","purl":"pkg:cargo/coreutils"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"0.8.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-5hgf-628x-mcqf/GHSA-5hgf-628x-mcqf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}