erase-install prior to v40.4 commit 2c31239 writes swiftDialog credential output to a hardcoded path /var/tmp/dialog.json. This allows an unauthenticated attacker to intercept admin credentials entered during reinstall/erase operations via creating a named pipe.
References
| Link | Resource |
|---|---|
| https://github.com/grahampugh/erase-install/commit/2c31239fb8519d87577514b3db9ddb0771232a21 | Patch |
| https://github.com/grahampugh/erase-install/pull/574 | Issue Tracking Patch |
| https://github.com/malvector/CVE-2025-70342 | Exploit Mitigation Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-03-04 15:16
Updated : 2026-06-17 10:03
NVD link : CVE-2025-70342
Mitre link : CVE-2025-70342
CVE.ORG link : CVE-2025-70342
JSON object : View
Products Affected
grahampugh
- erase-install
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
