VDB
CVE-2025-14307
CVE-2025-14307
PUBLISHED
CVSS 9.300000190734863 CRITICAL
An insecure temporary file creation vulnerability exists in the AutoExtract component of Robocode version 1.9.3.6. The createTempFile method fails to securely create temporary files, allowing attackers to exploit race conditions and potentially execute arbitrary code or overwrite critical files. This vulnerability can be exploited by manipulating the temporary file creation process, leading to potential unauthorized actions.
EPSS 0.33% · 26.6th percentile
Risk Scores
CVSS 4.0
9.300000190734863
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/AU:Y/R:U/V:D/RE:M/U:Red
EPSS Score
0.33%
26.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Maven | net.sf.robocode:robocode.battle | 0 |
| robocode | robocode | 1.9.3.6 |
| Robocode Project | Robocode | 1.9.3.6 |
Timeline
- Dec 9, 2025 CVE Published
- Dec 9, 2025 EPSS Score
- Dec 9, 2025 PoC Published
- Dec 9, 2025 PoC Published
- Dec 9, 2025 PoC Published
- Dec 10, 2025 CVE Updated
- Dec 14, 2025 EPSS Score
- Dec 18, 2025 EPSS Score
- Dec 23, 2025 EPSS Score
- Dec 27, 2025 EPSS Score
- Jan 1, 2026 EPSS Score
- Jan 5, 2026 EPSS Score