WordOps through 3.20.0 has a wo/cli/plugins/stackpref.py TOCTOU race condition because the confpath os.open does not use a mode parameter during file creation.
"https://github.com/pypa/advisory-database/blob/main/vulns/wordops/PYSEC-2024-175.yaml"