https://github.com/python/cpython/commit/802f1457ed6088a1687907593f8cbfff102c6925
commit: 802f1457ed6088a1687907593f8cbfff102c6925
branch: main
author: Mark Byrne <[email protected]>
committer: vstinner <[email protected]>
date: 2026-10-05T14:58:35Z
summary:

gh-79459 tempfile: Raise a ValueError if the prefix or suffix contains a 
directory (#150477)

Co-authored-by: Victor Stinner <[email protected]>
Co-authored-by: blurb-it[bot] <43283697+blurb-it[bot]@users.noreply.github.com>

files:
A Misc/NEWS.d/next/Library/2026-10-05-13-57-08.gh-issue-79459.2RgBDL.rst
M Lib/tempfile.py
M Lib/test/test_tempfile.py

diff --git a/Lib/tempfile.py b/Lib/tempfile.py
index ad81c5d3417b4c..82c1ee353117e9 100644
--- a/Lib/tempfile.py
+++ b/Lib/tempfile.py
@@ -119,11 +119,15 @@ def _sanitize_params(prefix, suffix, dir):
     output_type = _infer_return_type(prefix, suffix, dir)
     if suffix is None:
         suffix = output_type()
+    if _os.path.dirname(suffix):
+        raise ValueError("suffix can't contain a directory component")
     if prefix is None:
         if output_type is str:
             prefix = template
         else:
             prefix = _os.fsencode(template)
+    if _os.path.dirname(prefix):
+        raise ValueError("prefix can't contain a directory component")
     if dir is None:
         if output_type is str:
             dir = gettempdir()
diff --git a/Lib/test/test_tempfile.py b/Lib/test/test_tempfile.py
index cd960ed99117b6..2f7b8798daa8c9 100644
--- a/Lib/test/test_tempfile.py
+++ b/Lib/test/test_tempfile.py
@@ -2154,5 +2154,46 @@ def test_cleanup_safe(self):
         # platforms, but don't forget to update the docs.
         self.assertTrue(tempfile._rmtree_use_dir_fd)
 
+
+class TestMisc(BaseTestCase):
+    def test_prefix_suffix_error(self):
+        tests = [
+            f"dir{os.sep}name",
+            f"{os.sep}abs_name",
+        ]
+        if os.altsep is not None:
+            tests.extend((
+                f"dir{os.altsep}name",
+                f"{os.altsep}abs_name",
+            ))
+        if support.MS_WINDOWS:
+            tests.append('C:name')
+        tests.extend(tuple(os.fsencode(path) for path in tests))
+
+        PREFIX_ERR = "prefix can't contain a directory component"
+        SUFFIX_ERR = "suffix can't contain a directory component"
+        for value in tests:
+            with self.subTest(value):
+                # test prefix
+                with self.assertRaisesRegex(ValueError, PREFIX_ERR):
+                    tempfile.mkstemp(prefix=value)
+                with self.assertRaisesRegex(ValueError, PREFIX_ERR):
+                    tempfile.mkdtemp(prefix=value)
+                with self.assertRaisesRegex(ValueError, PREFIX_ERR):
+                    tempfile.TemporaryFile(prefix=value)
+                with self.assertRaisesRegex(ValueError, PREFIX_ERR):
+                    tempfile.NamedTemporaryFile(prefix=value)
+
+                # test suffix
+                with self.assertRaisesRegex(ValueError, SUFFIX_ERR):
+                    tempfile.mkstemp(suffix=value)
+                with self.assertRaisesRegex(ValueError, SUFFIX_ERR):
+                    tempfile.mkdtemp(suffix=value)
+                with self.assertRaisesRegex(ValueError, SUFFIX_ERR):
+                    tempfile.TemporaryFile(suffix=value)
+                with self.assertRaisesRegex(ValueError, SUFFIX_ERR):
+                    tempfile.NamedTemporaryFile(suffix=value)
+
+
 if __name__ == "__main__":
     unittest.main()
diff --git 
a/Misc/NEWS.d/next/Library/2026-10-05-13-57-08.gh-issue-79459.2RgBDL.rst 
b/Misc/NEWS.d/next/Library/2026-10-05-13-57-08.gh-issue-79459.2RgBDL.rst
new file mode 100644
index 00000000000000..2bbe77d6972e22
--- /dev/null
+++ b/Misc/NEWS.d/next/Library/2026-10-05-13-57-08.gh-issue-79459.2RgBDL.rst
@@ -0,0 +1,2 @@
+:mod:`tempfile` functions that take a ``prefix`` or ``suffix`` argument now 
raise a :exc:`ValueError` if they contain a directory component:
+:func:`tempfile.mkstemp`, :func:`tempfile.mkdtemp`, 
:func:`tempfile.TemporaryFile`, :func:`tempfile.NamedTemporaryFile`.

_______________________________________________
Python-checkins mailing list -- [email protected]
To unsubscribe send an email to [email protected]
https://mail.python.org/mailman3//lists/python-checkins.python.org
Member address: [email protected]

Reply via email to