bash-git-prompt 2
bash-git-prompt 2.6.1 through 2.7.1 insecurely uses the /tmp/git-index-private$$ file, which has a predictable name.
Exploitability
AV:L
AC:L
PR:N
UI:N
Scope
S:C
Impact
C:L
I:L
A:L
6.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Other
CWE-377