VDB

CVE-2025-14307

CVE-2025-14307 PUBLISHED CVSS 9.300000190734863 CRITICAL

An insecure temporary file creation vulnerability exists in the AutoExtract component of Robocode version 1.9.3.6. The createTempFile method fails to securely create temporary files, allowing attackers to exploit race conditions and potentially execute arbitrary code or overwrite critical files. This vulnerability can be exploited by manipulating the temporary file creation process, leading to potential unauthorized actions.

EPSS 0.33% · 26.6th percentile

Risk Scores

CVSS 4.0
9.300000190734863
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/AU:Y/R:U/V:D/RE:M/U:Red
EPSS Score
0.33%
26.6th percentile

Affected Products

VendorProductVersions
Mavennet.sf.robocode:robocode.battle0
robocoderobocode1.9.3.6
Robocode ProjectRobocode1.9.3.6

Timeline

  • Dec 9, 2025 CVE Published
  • Dec 9, 2025 EPSS Score
  • Dec 9, 2025 PoC Published
  • Dec 9, 2025 PoC Published
  • Dec 9, 2025 PoC Published
  • Dec 10, 2025 CVE Updated
  • Dec 14, 2025 EPSS Score
  • Dec 18, 2025 EPSS Score
  • Dec 23, 2025 EPSS Score
  • Dec 27, 2025 EPSS Score
  • Jan 1, 2026 EPSS Score
  • Jan 5, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›