CVE-2026-5958Disclosure

MEDIUMCVSS 2.1 · LOW

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

When sed is invoked with both -i (in-place edit) and --follow-symlinks, the function open_next_file() performs two separate, non-atomic filesystem operations on the same path: 1. resolves symlink to its target and stores the resolved path for determining when output is written, 2. opens the original symlink path (not the resolved one) to read the file. Between these two calls there is a race window. If an attacker atomically replaces the symlink with a different target during that window, sed will: read content from the new (attacker-chosen) symlink target and write the processed result to the path recorded in step 1. This can lead to arbitrary file overwrite with attacker-controlled content in the context of the sed process. This issue was fixed in version 4.10.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-367

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 3 mentions (2026-04-20); latest day: 1
  • 7 total mentions across 5 days

Deep dive

Activity timeline7 mentions / 5d
01223Mentions · 2026-04-20: 3Mentions · 2026-04-27: 1Mentions · 2026-04-28: 1Mentions · 2026-05-13: 1Mentions · 2026-05-15: 1PoC Mentioned / Linked · 2026-04-28: 1Exploit Tool / Code · 2026-04-27: 1Patch / Workaround · 2026-05-15: 1Technical Details · 2026-04-20: 3Technical Details · 2026-04-27: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-15: 104-2004-2704-2805-1305-15
Signal classification2 categories
Disclosure
685.7%
General
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-203
Disclosure3
2026-04-271
Disclosure1
2026-04-281
General1
2026-05-131
Disclosure1
2026-05-151
Disclosure1
Full discourse7 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-5958: GNU sed: TOCTOU race in sed -i --follow-symlinks https://www.openwall.com/lists/oss-security/2026/05/13/1 Fixed in 4.10 (2026-04-21)

    Post summary

    A TOCTOU race condition in GNU sed's --follow-symlinks option was disclosed and fixed in version 4.10.

    030731.2K
    4.7K followersView on X
  • kiran ghimire@cimihan1945
    General

    Most CVE writeups explain what happened. Few teach you how to think like an attacker. Just worked through CVE-2026-5958 step by step. Missed 1/5 questions - but learned way more. https://cveplayground.com #CyberSecurity #AppSec #CVE #BugBounty #InfoSec

    Post summary

    The user shares a learning experience on CVE-2026-5958 via cveplayground.com, indicating a walk-through but providing no exploit details, patches, or technical depth.

    0001076
    67 followersView on X
  • afine@afinePL
    Disclosure

    CVE-2026-5958: GNU sed 4.1e through 4.9 has a TOCTOU race condition. Run sed -i --follow-symlinks, and an attacker swapping a symlink between readlink() and open() causes sed to read from one file and write to another.

    Post summary

    The text discloses a TOCTOU race condition in GNU sed 4.1e‑4.9 and explains how an attacker can exploit it by swapping a symlink during sed’s "-i" operation with "--follow-symlinks".

    1000067
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5958 When sed is invoked with both -i (in-place edit) and --follow-symlinks, the function open_next_file() performs two separate, non-atomic filesystem operations on the sam… https://www.cve.org/CVERecord?id=CVE-2026-5958

    Post summary

    The excerpt provides a concise technical note on CVE-2026-5958, highlighting a race condition in sed, but contains no PoC, exploit, patch, or active exploitation information.

    00010265
    57.2K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    GNU Sed TOCTOU vulnerability (CVE-2026-5958) allows arbitrary file overwrite. Read more -> https://tinyurl.com/275m2696 #Security #Mageia https://t.co/11HKmdkmWO

    Post summary

    A new GNU Sed TOCTOU vulnerability (CVE-2026-5958) that permits arbitrary file overwrite has been disclosed, with a link for further details.

    0000038
    1.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5958 Race Condition Arbitrary File Overwrite in GNU sed with Symlink Following https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5958

    Post summary

    The text announces the CVE‑2026‑5958 vulnerability, describing a race condition that allows arbitrary file overwrite via symlink following in GNU sed, without mentioning PoC, exploit code, or patches.

    0000045
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5958 When sed is invoked with both -i (in-place edit) and --follow-symlinks, the function open_next_file() performs two separate, non-atomic filesystem operations on the sam… https://www.cve.org/CVERecord?id=CVE-2026-5958 ----- Traducción: CVE-2026-5958 Cua… http://infoflow.cloud`

    Post summary

    The notice discloses CVE-2026-5958, detailing a non-atomic filesystem operation issue in sed when using -i and --follow-symlinks; no PoC, exploit, patch, or active exploitation is mentioned.

    0000035
    72 followersView on X

Explore more