CVE-2025-68146Disclosure(tox-dev / filelock)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

filelock is a platform-independent file lock for Python. In versions prior to 3.20.1, a Time-of-Check-Time-of-Use (TOCTOU) race condition allows local attackers to corrupt or truncate arbitrary user files through symlink attacks. The vulnerability exists in both Unix and Windows lock file creation where filelock checks if a file exists before opening it with O_TRUNC. An attacker can create a symlink pointing to a victim file in the time gap between the check and open, causing os.open() to follow the symlink and truncate the target file. All users of filelock on Unix, Linux, macOS, and Windows systems are impacted. The vulnerability cascades to dependent libraries. The attack requires local filesystem access and ability to create symlinks (standard user permissions on Unix; Developer Mode on Windows 10+). Exploitation succeeds within 1-3 attempts when lock file paths are predictable. The issue is fixed in version 3.20.1. If immediate upgrade is not possible, use SoftFileLock instead of UnixFileLock/WindowsFileLock (note: different locking semantics, may not be suitable for all use cases); ensure lock file directories have restrictive permissions (chmod 0700) to prevent untrusted users from creating symlinks; and/or monitor lock file directories for suspicious symlinks before running trusted applications. These workarounds provide only partial mitigation. The race condition remains exploitable. Upgrading to version 3.20.1 is strongly recommended.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59CWE-362CWE-367

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • filelock

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
filelock

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-19: 1Technical Details · 2026-04-19: 104-19
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • The Agent Times@TheAgentTimes
    Disclosure

    A path traversal vulnerability (CVE-2025-68146) in the OpenHands AI agent framework allowed sandbox escape and arbitrary file reads, exposing systemic security flaws in how agent frameworks handle tool execution, sandboxing, and logging. https://theagenttimes.com/articles/critical-cve-in-openhands-framework-reveals-why-our-security-4234c986 #AIAgents https://t.co/p6JxxBje4d

    Post summary

    The post discloses CVE-2025-68146, describing a path traversal flaw in OpenHands that allows sandbox escape and file reads, but it does not provide any PoC, exploit code, or patch information.

    000005
    87 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptox-devfilelock-python-

Explore more