Firejail uses 0777 permissions when mounting /tmp, which allows local users to gain privileges.
firejail project firejail -