Incorrect Permission Assignment for Critical Resource Affecting seffaflik package, versions [,0.0.9)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-SEFFAFLIK-13671308
  • published23 Oct 2025
  • disclosed22 Oct 2025
  • creditUnknown

Introduced: 22 Oct 2025

NewCVE-2025-61035  (opens in a new tab)
CWE-732  (opens in a new tab)

How to fix?

Upgrade seffaflik to version 0.0.9 or higher.

Overview

seffaflik is an EPİAŞ tarafından Şeffaflık Platformunda yayımlanmakta olan verileri çekmek için tasarlanmış Python kütüphanesi

Affected versions of this package are vulnerable to Incorrect Permission Assignment for Critical Resource via the creation of .kimlik and .seffaflik files with overly permissive permissions and the absence of symlink checks when writing to .kimlik. An attacker can access sensitive information or overwrite arbitrary files by exploiting these insecure file operations.

References

CVSS Base Scores

version 4.0
version 3.1