I was expecting some obscure bug in signature verification or something but nope it’s a basic tempfile attack, the sort most of us learned how to avoid in shell scripts decades ago.
> If an attacker pre-creates the file with relaxed access permissions, then data stored in the temporary file by the application may be accessed, modified or corrupted by an attacker.
https://owasp.org/www-community/vulnerabilities/Insecure_Tem...
With that said, I definitely ill be looking out for this in the future.
[1] I have unintentionally protected against this by using unique names for my temp files.